Data Processing Addendum
Last updated: 2 October 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Use or other written agreement (the "Agreement") between Agently, Inc. ("Agently") and the customer that has agreed to it ("Customer"). It applies when Agently processes Customer Personal Data on Customer's behalf in providing the Service, and that processing is subject to Data Protection Laws.
Customer accepts this DPA by accepting the Agreement. No signature is needed. If Customer needs a countersigned copy, email support@agently.dev.
1. Definitions
Terms not defined here have the meaning given in the Agreement or in the GDPR.
-
"Data Protection Laws" means the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and any other data protection law that applies to the processing of Customer Personal Data under the Agreement.
-
"GDPR" means Regulation (EU) 2016/679; "UK GDPR" means the GDPR as it forms part of the law of the United Kingdom.
-
"Customer Personal Data" means personal data contained in content that Customer and its users submit to, store in, or connect to the Service, which Agently processes on Customer's behalf.
-
"Subprocessor" means a third party engaged by Agently that processes Customer Personal Data.
-
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
-
"SCCs" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
-
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force 21 March 2022).
2. Roles
2.1 For Customer Personal Data, Customer is the controller (or a processor acting for its own controllers) and Agently is the processor (or subprocessor).
2.2 Agently is a separate controller of the personal data it processes for its own business purposes, such as account administration, billing, security and analytics, as described in its Privacy Notice. This DPA does not apply to that processing.
3. Details of the Processing
-
Subject matter: providing the Service under the Agreement.
-
Duration: the term of the Agreement, plus the period until deletion under section 11.
-
Nature and purpose: hosting, storing, indexing, searching, organizing and displaying Customer Personal Data; running AI assistants, agents, routines and automations at the direction of Customer's users; exchanging data with tools Customer's users connect; sending messages and taking actions those users initiate or approve; providing support; and keeping the Service secure.
-
Categories of data subjects: Customer's users; and Customer's employees, contractors, customers, prospects, partners, investors and other people whose personal data appears in content Customer submits or connects.
-
Types of personal data: identification and contact details (such as names, email addresses, phone numbers and job titles); the content of documents, messages, emails, calendar events, tasks, notes and conversations; and any other personal data Customer chooses to submit or connect.
-
Special categories: Agently does not require special categories of data. Customer decides whether to submit any and is responsible for having a lawful basis to do so.
-
Frequency: continuous, for as long as Customer uses the Service.
4. Agently's Obligations
Agently will:
4.1 process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law, in which case Agently will tell Customer before processing unless the law prohibits it. The Agreement, this DPA and Customer's use and configuration of the Service are Customer's complete instructions. Agently will tell Customer if, in its opinion, an instruction infringes Data Protection Laws;
4.2 ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations;
4.3 implement the security measures in section 6;
4.4 engage Subprocessors only as set out in section 7;
4.5 assist Customer, taking into account the nature of the processing, in responding to requests from data subjects, as set out in section 8;
4.6 assist Customer in meeting its obligations on security, Security Incident notification, data protection impact assessments and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to Agently;
4.7 delete or return Customer Personal Data at the end of the Service as set out in section 11; and
4.8 make available the information necessary to demonstrate compliance with this section and allow for audits as set out in section 10.
5. Customer's Obligations
Customer is responsible for the lawfulness of its instructions and of the Customer Personal Data it submits or connects, including having a lawful basis and giving any notices required by Data Protection Laws, and for how its users configure and use the Service, including the tools and AI assistants they connect.
6. Security
Agently maintains appropriate technical and organizational measures to protect Customer Personal Data, including:
-
Encryption in transit: data is transmitted to and from the Service, and between the Service and its providers, over TLS.
-
Encryption at rest: databases and file storage are encrypted at rest by Agently's infrastructure providers.
-
Credential protection: integration access tokens are stored in a dedicated credential vault operated by Agently's integration provider, not in the application database; credentials for custom connectors (remote MCP servers) are encrypted with AES-256 before they are stored; workspace API keys and MCP access tokens are stored only as one-way hashes; passwords are handled by Agently's identity provider and never stored in plain text.
-
Workspace isolation and access control: every request is checked against the user's workspace membership, and data is scoped to the workspace it belongs to.
-
Internal access: access to production systems is limited to authorized personnel who need it.
-
Audit trail: actions the AI assistant performs through a connected integration are recorded in an audit log attributable to the user who initiated them.
Agently may update these measures from time to time, provided the overall level of protection is not reduced.
7. Subprocessors
7.1 Customer gives Agently general authorization to engage Subprocessors. The current list is at agently.dev/subprocessors.
7.2 Agently will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains responsible for each Subprocessor's performance of its obligations.
7.3 Agently will give at least 30 days' notice of a new Subprocessor by updating the Subprocessors page, and by email to Customers who ask to receive that notice at support@agently.dev.
7.4 Customer may object to a new Subprocessor on reasonable data protection grounds by emailing support@agently.dev within the notice period. The parties will discuss the objection in good faith. If they cannot resolve it, Customer may terminate the affected part of the Service by written notice, and Agently will refund any prepaid fees for the period after termination.
8. Data Subject Requests
If Agently receives a request from a data subject about Customer Personal Data, it will tell the data subject to contact Customer and will not respond itself except to confirm the request was passed on, unless Customer authorizes it or the law requires otherwise. The Service lets Customer's users find, correct and delete content and export pages, and Agently will provide reasonable further assistance where Customer cannot fulfil a request through the Service.
9. Security Incidents
Agently will notify Customer without undue delay after becoming aware of a Security Incident, by email to the workspace owner. The notice will describe, as far as it is then known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Agently will provide further information as it becomes available and will take reasonable steps to contain and remedy the incident. Notifying Customer is not an admission of fault.
10. Audits
On written request, and no more than once a year unless required by a supervisory authority or after a Security Incident, Agently will provide information reasonably necessary to demonstrate compliance with this DPA, including written answers to reasonable security questionnaires and relevant documentation. If that information is not sufficient to demonstrate compliance, or a supervisory authority requires it, Customer may carry out an audit, at its own cost, with at least 30 days' notice, during business hours, without access to other customers' data, and subject to reasonable confidentiality terms.
11. Deletion and Return
During the Agreement, Customer's users can export and delete content through the Service, or ask support@agently.dev for help. When the Agreement ends, or when Customer deletes its workspace, Agently will delete Customer Personal Data within 30 days, and copies in encrypted backups will be overwritten within a further 30 days, unless the law requires Agently to keep it. Before the end of the Agreement, Customer may ask Agently for a copy of its content.
12. International Transfers
12.1 Agently processes Customer Personal Data in the United States, and its Subprocessors may process it in the countries listed on the Subprocessors page.
12.2 EU transfers. Where Customer Personal Data is transferred from the European Economic Area to Agently in a country without an adequacy decision, the SCCs are incorporated into this DPA by reference as follows:
-
Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor;
-
Clause 7 (docking clause) applies;
-
in Clause 9, Option 2 (general written authorization) applies, with the notice period in section 7.3;
-
the optional language in Clause 11 does not apply;
-
in Clause 13, the competent supervisory authority is the one determined under that Clause based on Customer's establishment or, if Customer is not established in the EEA, its representative;
-
in Clause 17, the SCCs are governed by the law of Ireland, and in Clause 18 disputes are resolved by the courts of Ireland;
-
Annex I is completed by the parties' details in the Agreement and by section 3 of this DPA, Annex II by section 6, and Annex III by the Subprocessors page.
12.3 UK transfers. For transfers from the United Kingdom, the UK Addendum is incorporated by reference. Tables 1 to 3 are completed with the information in section 12.2 and this DPA, and in Table 4 either party may end the UK Addendum as set out in its Section 19.
12.4 Swiss transfers. For transfers from Switzerland, the SCCs apply as set out in section 12.2, with these changes: references to the GDPR include the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the term "member state" does not exclude data subjects in Switzerland from bringing claims in their place of habitual residence.
12.5 Agently will ensure that its transfers of Customer Personal Data to Subprocessors are protected by an appropriate safeguard under Data Protection Laws, such as the SCCs or a Subprocessor's certification under the EU-US Data Privacy Framework.
13. General
13.1 Precedence. If there is a conflict, the SCCs (where they apply) prevail over this DPA, and this DPA prevails over the rest of the Agreement for the processing of Customer Personal Data.
13.2 Liability. Each party's liability under this DPA is subject to the limitations in the Agreement, except that nothing in this DPA limits either party's liability to data subjects under the SCCs or Data Protection Laws where such a limit is not permitted.
13.3 Changes. Agently may update this DPA to reflect changes in Data Protection Laws, in the Service or in its Subprocessors, provided the update does not materially reduce the protection given to Customer Personal Data. The current version is always at agently.dev/dpa.
13.4 Contact. Questions about this DPA can be sent to support@agently.dev.