1. Parties and roles
This Data Processing Agreement ("DPA") is between Engineered Agents AI, a Delaware company headquartered in Columbus, Ohio ("EA", the "Processor"), and the customer that has accepted our Terms of Service or signed an Order Form under our Master Service Agreement (the "Customer", the "Controller"). Together, those documents are the "Agreement".
For the personal data described in Annex 1, the Customer is the controller (or a processor acting for its own controllers) and EA is the processor. EA processes that data only to provide the services and only on the Customer's documented instructions. The Agreement, the Customer's configuration of the services, and the approvals the Customer gives inside the platform are those instructions.
This DPA applies where data protection law applies to the processing, including the EU and UK GDPR, the California Consumer Privacy Act as amended, and comparable US state laws. Where such law does not apply, EA still follows the security and confidentiality commitments in this DPA.
2. Processor obligations
EA will:
- Process personal data only on the Customer's documented instructions, including with regard to transfers, unless required by law to do otherwise, in which case EA will inform the Customer before processing unless the law prohibits it.
- Ensure that every person EA authorizes to process the data is bound by confidentiality.
- Implement and maintain the technical and organizational measures in Annex 2.
- Engage sub-processors only as permitted by section 4.
- Assist the Customer, taking into account the nature of the processing, in responding to requests from data subjects (section 5) and in meeting its obligations on security, breach notification, impact assessments, and consultation with supervisory authorities.
- Delete or return the personal data at the end of the services (section 7).
- Make available the information needed to demonstrate compliance and allow for audits (section 8).
- Inform the Customer promptly if EA believes an instruction infringes data protection law.
3. AI features and model providers
The services use large language models operated by the sub-processors listed in Annex 3. Content sent to those providers is sent to provide the feature the Customer invoked, under provider terms that prohibit using the content to train models. EA does not use Customer personal data to train models of its own.
Agents in the platform act within the accounts and permissions the Customer connects and under the approval settings the Customer chooses. Where the Customer enables an agent to send, post, or publish without a per-item approval, the Customer instructs EA to do so on its behalf and remains the controller of the resulting communications.
4. Sub-processors
The Customer gives general authorization for EA to engage the sub-processors in Annex 3. EA will impose on each sub-processor data protection obligations no less protective than this DPA and remains liable for their performance.
EA will give at least 30 days' notice before adding or replacing a sub-processor that processes Customer personal data, by updating this page and emailing the account owner. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected service and receive a refund of prepaid fees for the unused term.
Services the Customer connects at its own direction (for example its mailbox, CRM, accounting, advertising, marketplace, or social media accounts) are not EA sub-processors. Those providers process data under the Customer's own agreements with them; EA exchanges data with them only as the Customer configures.
5. Data subject requests
If EA receives a request from a data subject about personal data processed for the Customer, EA will direct the data subject to the Customer, inform the Customer within 5 business days, and not respond substantively unless the Customer instructs it to or the law requires it. EA will assist the Customer with access, correction, deletion, portability, restriction, and objection requests through the platform's export and deletion features and, where those are not enough, through reasonable manual assistance.
6. Personal data breach
EA will notify the Customer without undue delay, and in any case within 72 hours, after confirming a personal data breach affecting Customer personal data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. EA will supplement the notice as information becomes available and will cooperate with the Customer's own notifications. Notices go to the account owner's email and to any security contact the Customer has registered.
7. Return and deletion
During the term, the Customer can export its data from the platform and delete records itself. At the end of the services, EA will, at the Customer's choice, return the personal data in a machine-readable format or delete it. Absent a choice, EA deletes it within 90 days of termination, and deletes it from rolling backups within 30 days after that, except where the law requires longer retention (for example billing records). EA will confirm deletion in writing on request.
8. Audits and information
On request, no more than once in any 12-month period unless a breach or a supervisory authority requires otherwise, EA will provide a written description of its security program, completed security questionnaires, and any third-party assessment reports it holds. If those do not reasonably satisfy the Customer's legal obligations, the Customer or an independent auditor bound by confidentiality may audit EA's relevant systems on 30 days' notice, during business hours, at the Customer's cost, in a way that does not compromise other customers' data.
9. International transfers
EA processes data in the United States (AWS us-east-2). For personal data subject to the EU or UK GDPR, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), with the Customer as data exporter and EA as data importer, and for UK data the UK International Data Transfer Addendum. Annex 1 and Annex 2 of this DPA serve as the corresponding annexes to the Clauses. Where a Customer needs the Clauses executed as a separate document, EA will sign them on request.
10. US state privacy laws
Where the CCPA or a comparable US state law applies, EA acts as a service provider or processor. EA will not sell or share Customer personal data, retain, use, or disclose it for any purpose other than providing the services, or combine it with data from other sources except as the law permits for a service provider. EA will notify the Customer if it can no longer meet these obligations, and the Customer may take reasonable steps to stop and remediate unauthorized use.
11. Term, liability, and precedence
This DPA lasts as long as EA processes personal data for the Customer. Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, taken together as a single cap, not a separate one. Where this DPA conflicts with the Agreement on the protection of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
Annex 1. Details of the processing
- Subject matter and purpose: operating AI agents and software modules that run business functions the Customer has enabled: sales, marketing, operations, finance, and support.
- Duration: the term of the Agreement plus the deletion period in section 7.
- Nature of processing: storage, retrieval, analysis, drafting, sending, and publishing on the Customer's instruction; automated processing by language models; no automated decisions with legal or similarly significant effects on individuals.
- Categories of data subjects: the Customer's staff and authorized users; the Customer's customers, prospects, suppliers, and business contacts; recipients of communications the Customer sends through the services; visitors who interact with the Customer's connected websites and social accounts.
- Categories of personal data: names, business and personal contact details, job titles and employers; contents of emails, messages, documents, and meeting notes the Customer connects or uploads; order, invoice, quote, and payment records (not full card numbers); social media handles, comments, and engagement data; account credentials for connected services (encrypted at rest); usage logs.
- Special categories: not intended. The Customer agrees not to connect or upload data revealing health, biometric, genetic, sexual orientation, religious, political, or union information unless agreed in writing with additional safeguards.
Annex 2. Technical and organizational measures
- Tenant isolation enforced in the database with PostgreSQL Row-Level Security, so one customer's records are invisible to every other customer's session.
- TLS 1.2 or better for all traffic in transit; AES-256 encryption at rest for databases, backups, and object storage; envelope encryption for integration credentials in a per-tenant secrets store.
- Authentication with hashed passwords, single sign-on where enabled, HTTP-only session cookies, and role-based access (owner, admin, member) inside each tenant.
- Agent actions that reach outside the platform (sending, posting, publishing, paying) run behind approval controls the Customer configures, with an audit trail of what was sent, by which agent, and who approved it.
- Least-privilege staff access, logged and reviewed; production access limited to named engineers over authenticated channels.
- Daily database backups retained 30 days, cross-region copies, tested restores.
- Dependency and vulnerability monitoring in continuous integration, security patches within 30 days of disclosure and sooner for critical issues, error monitoring in production.
- Sub-processors bound by written data protection terms; model providers bound by no-training terms.
- Incident response with the notification timeline in section 6.
Annex 3. Sub-processors
Current as of the "Last updated" date above. Changes follow section 4.
- Amazon Web Services (US): hosting, database, object storage, secrets, backups.
- Stripe (US): payment processing for BOS Platform subscriptions.
- Anthropic (US): primary language model provider for AI features.
- OpenAI (US): language models for some features and as a fallback.
- Google (US): Gemini models, embeddings, and Workspace integration where the Customer connects it.
- OpenRouter (US): routing of some model calls to third-party model providers, including DeepSeek, under no-training terms.
- Brevo (France / EU): transactional and agent email delivery.
- Twilio SendGrid (US): inbound email parsing for agent mailboxes.
- Twilio (US): SMS and voice, where the Customer enables them.
- Telegram (UAE): owner notifications and approvals, where the Customer enables them.
- Sentry (US): error reporting for production services.
- Shopify (Canada / US): the platform TierPilot runs on, for TierPilot customers.
Contact
Engineered Agents AI
Columbus, Ohio, United States
privacy@engineeredagents.ai for data protection matters, security@engineeredagents.ai for incidents.