Data Processing Agreement
Last updated:: 2026-08-06
This DPA forms part of the Terms of Service and governs the processing of personal data by HostAgentics on behalf of customers (Article 28 GDPR and equivalent frameworks).
1. Roles
The customer is the controller; HostAgentics is the processor. Where the customer acts as processor for its own customers, HostAgentics is a sub-processor.
2. Scope of processing
Processing is limited to: account and billing data, runtime configuration and content, usage and health telemetry, and support correspondence — solely to provide, secure, and improve the service.
3. Sub-processors
Current sub-processors are listed on the Subprocessors page. Customers may object to new sub-processors within 14 days of notice.
4. Security
HostAgentics maintains organizational and technical measures including encryption at rest, encrypted secrets, per-runtime isolation, access controls, and audit logging. Customers are responsible for their own credentials and keys.
5. Data subject rights
HostAgentics assists the controller in responding to data subject requests (access, correction, deletion, portability) via the customer dashboard tools or support channels.
6. Breach notification
HostAgentics notifies the controller without undue delay after becoming aware of a personal data breach affecting controller data.
7. Deletion
On termination, customer data is retained for the retention period, then deleted or returned at the customer option where technically feasible.
8. Jurisdiction
Standard Contractual Clauses apply for transfers outside the EEA where required; the parties adopt them by reference to this DPA.
Questions: [email protected]

