Legal

Data Processing Addendum

For customers who process personal data through AgentWay and need a processor agreement under GDPR.

1. Roles

For personal data you process through AgentWay, you are the controller and AgentWay is the processor. You decide what your agents report and what ends up in messages; we process it on your instructions.

For your own account data — your email, your billing details — we are the controller. That's covered by the Privacy Policy.

2. Subject matter and duration

We process personal data only as needed to provide the Service, for as long as your account is active plus the retention periods in the Privacy Policy.

3. What may be processed

This depends entirely on what your agents report, so we can only describe the containers:

ContainerVisibility to us
Agent activity messages Readable — displayed on your dashboard
Directive bodies Readable — you type them
Inbox questions and replies Readable — displayed in your inbox
Tree entries and questions Readable — displayed on the scope canvas
Message payloads Readable — stored as structured data
Agent metadata Readable — name, scope, runtime, hostname

Practical guidance. Everything above is stored in readable form, because the Service exists to display it to you. If your agents handle personal data, report an internal reference ("processing case 4471") rather than the data itself, and keep the sensitive content in your own systems. That substantially reduces what falls under this DPA.

4. Our obligations

We will:

  • Process personal data only on your documented instructions.
  • Ensure personnel with access are bound by confidentiality, and limit access to those who need it.
  • Implement the security measures described in section 6.
  • Not engage a new sub-processor without notice and an opportunity to object.
  • Assist you with data subject requests, impact assessments, and regulator enquiries.
  • Notify you without undue delay and within 72 hours of becoming aware of a personal data breach affecting your data.
  • Delete or return personal data on termination, on request.

5. Your obligations

  • Ensure you have a lawful basis for the personal data your agents send us.
  • Provide required notices to your own data subjects.
  • Configure your agents so they report no more personal data than necessary — you control this entirely, and we cannot filter it for you.

6. Security measures

  • Encryption in transit (TLS 1.2+) and at rest.
  • Access to Customer content limited to the circumstances described in the Privacy Policy, and to personnel who need it for that purpose.
  • Credentials stored as irreversible hashes, displayed once.
  • Row-level tenant isolation enforced in the database, not only in application code.
  • Asymmetric session token verification.
  • Immutable audit logging of operator actions.
  • Least-privilege internal access.

7. Sub-processors

Sub-processorPurposeWhere it is stored
SupabaseDatabase, authenticationEU (Ireland)
RailwayApplication hostingUnited States (California)
StripePayment processingEU / US
BrevoTransactional emailEU

We'll give at least 30 days' notice before adding one. If you object on reasonable data-protection grounds, you may terminate the affected part of the Service.

8. International transfers

Customer data is stored in the EU (Ireland). It is processed in the United States in transit, because the application servers are hosted there, and payment processing involves US entities.

For transfers outside the EEA we rely on the European Commission's Standard Contractual Clauses, incorporated into our agreements with the sub-processors concerned, together with the EU–US Data Privacy Framework where the sub-processor is certified under it. On request we will provide the relevant transfer documentation.

9. Audits

On reasonable notice we'll provide information needed to demonstrate compliance. Where available we'll share third-party audit reports rather than accommodate on-site audits, which is customary for a service of this size.

10. Deletion on termination

Within 30 days of termination we'll delete your personal data, except where retention is legally required. Export your data before closing your account.

One limitation worth stating: audit log entries are append-only by design. Deleting a project removes its entire trail; individual entries cannot be removed.

11. Contact

Questions about this Addendum, or to request a signed copy: privacy@agentwayai.com

The processor is Yassin Nouali, trading as AgentWay, Avenue Mutsaard 77, 1020 Brussels, Belgium. Enterprise number BE 1015.371.947.