Legal
Data Processing Addendum
For customers who process personal data through AgentWay and need a processor agreement under GDPR.
1. Roles
For personal data you process through AgentWay, you are the controller and AgentWay is the processor. You decide what your agents report and what ends up in messages; we process it on your instructions.
For your own account data — your email, your billing details — we are the controller. That's covered by the Privacy Policy.
2. Subject matter and duration
We process personal data only as needed to provide the Service, for as long as your account is active plus the retention periods in the Privacy Policy.
3. What may be processed
This depends entirely on what your agents report, so we can only describe the containers:
| Container | Visibility to us |
|---|---|
| Agent activity messages | Readable — displayed on your dashboard |
| Directive bodies | Readable — you type them |
| Inbox questions and replies | Readable — displayed in your inbox |
| Tree entries and questions | Readable — displayed on the scope canvas |
| Message payloads | Readable — stored as structured data |
| Agent metadata | Readable — name, scope, runtime, hostname |
Practical guidance. Everything above is stored
in readable form, because the Service exists to display it to
you. If your agents handle personal data, report an internal
reference ("processing case 4471") rather than the
data itself, and keep the sensitive content in your own systems.
That substantially reduces what falls under this DPA.
4. Our obligations
We will:
- Process personal data only on your documented instructions.
- Ensure personnel with access are bound by confidentiality, and limit access to those who need it.
- Implement the security measures described in section 6.
- Not engage a new sub-processor without notice and an opportunity to object.
- Assist you with data subject requests, impact assessments, and regulator enquiries.
- Notify you without undue delay and within 72 hours of becoming aware of a personal data breach affecting your data.
- Delete or return personal data on termination, on request.
5. Your obligations
- Ensure you have a lawful basis for the personal data your agents send us.
- Provide required notices to your own data subjects.
- Configure your agents so they report no more personal data than necessary — you control this entirely, and we cannot filter it for you.
6. Security measures
- Encryption in transit (TLS 1.2+) and at rest.
- Access to Customer content limited to the circumstances described in the Privacy Policy, and to personnel who need it for that purpose.
- Credentials stored as irreversible hashes, displayed once.
- Row-level tenant isolation enforced in the database, not only in application code.
- Asymmetric session token verification.
- Immutable audit logging of operator actions.
- Least-privilege internal access.
7. Sub-processors
| Sub-processor | Purpose | Where it is stored |
|---|---|---|
| Supabase | Database, authentication | EU (Ireland) |
| Railway | Application hosting | United States (California) |
| Stripe | Payment processing | EU / US |
| Brevo | Transactional email | EU |
We'll give at least 30 days' notice before adding one. If you object on reasonable data-protection grounds, you may terminate the affected part of the Service.
8. International transfers
Customer data is stored in the EU (Ireland). It is processed in the United States in transit, because the application servers are hosted there, and payment processing involves US entities.
For transfers outside the EEA we rely on the European Commission's Standard Contractual Clauses, incorporated into our agreements with the sub-processors concerned, together with the EU–US Data Privacy Framework where the sub-processor is certified under it. On request we will provide the relevant transfer documentation.
9. Audits
On reasonable notice we'll provide information needed to demonstrate compliance. Where available we'll share third-party audit reports rather than accommodate on-site audits, which is customary for a service of this size.
10. Deletion on termination
Within 30 days of termination we'll delete your personal data, except where retention is legally required. Export your data before closing your account.
One limitation worth stating: audit log entries are append-only by design. Deleting a project removes its entire trail; individual entries cannot be removed.
11. Contact
Questions about this Addendum, or to request a signed copy: privacy@agentwayai.com
The processor is Yassin Nouali, trading as AgentWay, Avenue Mutsaard 77, 1020 Brussels, Belgium. Enterprise number BE 1015.371.947.