Legal
Data Processing Agreement
Version 1.1 — Effective 2026-05-10 · Back to summary
This Data Processing Agreement ("DPA") forms part of the Coagentic Terms of Service or any equivalent master services agreement (the "Agreement") between Coagentic ("Processor") and the customer ("Controller") that subscribes to the Coagentic platform.
When applicable law (including the EU GDPR, UK GDPR, Swiss FADP, California CCPA/CPRA, and Türkiye's KVKK) requires a written contract for the processing of Personal Data, this DPA governs the parties' obligations.
By using the Coagentic platform on or after the effective date above, the Controller agrees to this DPA.
1. Definitions
- Controller, Processor, Sub-processor, Personal Data, Data Subject, Process / Processing, and Personal Data Breach have the meanings given to them in the GDPR.
- Customer Data means data the Controller (and its end users) submits to the Coagentic platform.
- Services means the Coagentic SaaS platform and any related professional services.
- Standard Contractual Clauses (SCCs) means the European Commission's Standard Contractual Clauses adopted under Decision 2021/914 of 4 June 2021.
2. Subject matter, duration, nature and purpose
| Subject matter | Provision of the Services as described in the Agreement. |
| Duration | For the term of the Agreement, plus any post-termination retention period agreed below. |
| Nature and purpose | Hosting Customer Data; running AI models on prompts the Controller submits; storing and indexing project files, databases, conversations, integrations, and analytics. |
| Type of Personal Data | Names, email addresses, profile photos, IP addresses, device/usage telemetry, AI prompts and responses, content the Controller chooses to upload, payment metadata (handled exclusively by Polar). |
| Categories of Data Subjects | Controller's authorised users, employees, contractors, end customers, prospects, and any other individuals whose data the Controller chooses to process via the Services. |
The Processor will not process Personal Data for any other purpose unless required by law.
3. Processor obligations
The Processor will:
- Process only on documented instructions. The Agreement, this DPA, and lawful in-product configuration constitute the Controller's documented instructions. If the Processor believes an instruction violates applicable law, it will inform the Controller without delay.
- Confidentiality. Ensure that personnel authorised to process Personal Data are bound by appropriate confidentiality obligations.
- Security. Implement and maintain the technical and organisational measures described in Annex A.
- Sub-processors. Engage sub-processors only as set out in §6.
- Assist the Controller. Provide reasonable assistance with data subject requests, DPIAs, and prior consultations with supervisory authorities (Articles 32–36 GDPR).
- Personal Data Breach. Notify the Controller without undue delay (and in any event within 72 hours after becoming aware) of any Personal Data Breach involving Customer Data, providing the information required under Article 33(3) GDPR.
- End of services. Upon termination, delete or return all Customer Data within 30 days unless retention is required by applicable law.
- Audits. Once per 12-month period, the Controller may, with at least 30 days' written notice, request an audit limited to information required to verify compliance with this DPA. The audit may be satisfied by the Processor providing a then-current third-party audit report (e.g. SOC 2 Type II) or equivalent certification once available.
4. Controller obligations
The Controller will:
- Lawful basis. Establish and maintain a lawful basis for the Processor's processing of Customer Data on its behalf.
- Notice and consent. Provide all required notices and obtain all necessary consents from Data Subjects before submitting Personal Data to the Services.
- Configuration. Configure the Services (e.g. data retention windows, integrations, sub-processor regions) consistently with its compliance obligations.
- Lawful instructions. Issue instructions that comply with applicable data-protection law.
5. Data subject rights
The Processor will, taking into account the nature of the processing, assist the Controller by providing in-product tools (export, deletion, restriction) and, where those tools are insufficient, by providing reasonable assistance with responding to requests from Data Subjects exercising rights under Articles 12–22 GDPR (or equivalent local law).
If the Processor receives a Data Subject request directly, it will, unless legally prohibited, inform the Data Subject to contact the Controller and notify the Controller without undue delay.
6. Sub-processors
The Controller grants a general authorisation to engage the sub-processors listed in Annex B. The Processor will:
- Maintain an up-to-date list of sub-processors at coagentic.work/legal/subprocessors.
- Notify the Controller (via in-product notice or email) at least 14 days before adding or replacing a sub-processor.
- Impose obligations on each sub-processor that are no less protective than this DPA.
- Remain liable for the acts and omissions of each sub-processor.
The Controller may object to a new sub-processor on reasonable data-protection grounds within 14 days of notice. If the parties cannot resolve the objection in good faith, the Controller may terminate the affected portion of the Services and receive a pro-rata refund of pre-paid fees.
Third-party services the Controller chooses to connect to its own projects (e.g. payment providers, email providers, SMS gateways, analytics) are processors engaged by the Controller, not sub-processors of Coagentic. The Controller is responsible for executing any required agreements with those providers directly.
7. International transfers
Where the Services involve transfers of Personal Data from the EEA, UK, or Switzerland to a country that the European Commission (or applicable authority) has not deemed to provide adequate protection, the parties agree that:
- The EU SCCs (Module Two — Controller to Processor) are incorporated by reference, with: Clause 7 ("docking") enabled; Clause 9(a) Option 2 (general authorisation, with the notice period in §6.2 above); Clause 11(a) — independent dispute-resolution body not added; Clause 17 — governing law: Ireland; Clause 18 — competent court: Dublin, Ireland; Annex I.A populated with the parties' identities (taken from the Agreement); Annex I.B populated by §2 of this DPA; Annex I.C — supervisory authority of the EEA member state of the Controller; Annex II populated by Annex A of this DPA.
- For UK transfers, the UK International Data Transfer Addendum (issued by the ICO) is incorporated, with the EU SCCs above as the approved transfer mechanism.
- For Swiss transfers, references to the GDPR are read as references to the FADP, references to "EU" / "Member State" include Switzerland, and the FDPIC is the competent supervisory authority.
8. CCPA / CPRA addendum (California)
To the extent the Processor processes "personal information" of California residents on behalf of the Controller within the meaning of the CCPA/CPRA, the Processor:
- Acts as a service provider (or contractor where applicable);
- Will not sell or share personal information;
- Will not retain, use, or disclose personal information outside the direct business relationship between the parties or for any purpose other than the business purposes specified in the Agreement;
- Certifies that it understands the restrictions in this section.
9. KVKK addendum (Türkiye)
Where the Controller is established in Türkiye or processes data of individuals in Türkiye and KVKK applies:
- The Controller is the "veri sorumlusu" and the Processor is the "veri işleyen".
- Cross-border transfers comply with Article 9 KVKK; the Controller is responsible for any explicit consents required.
- The technical and organisational measures in Annex A satisfy the KVKK Authority's published guidance on data security.
10. Liability
The parties' aggregate liability under this DPA is subject to the limitations of liability in the Agreement.
11. Conflict and order of precedence
In case of conflict, the order of precedence is: (i) the SCCs / UK Addendum where applicable, (ii) this DPA, (iii) the Agreement.
12. Changes
The Processor may update this DPA to reflect changes in applicable law or platform architecture. Material changes will be communicated to the Controller's billing-contact email address and posted at coagentic.work/legal/dpa.
Annex A — Technical and organisational measures
| Network security | All traffic served via HTTPS (TLS 1.2+); HSTS enabled on platform domains. WAF and rate-limiting at the edge (Cloudflare). |
| Encryption at rest | Postgres volumes are encrypted at the disk layer by the hosting provider. Integration credentials (Polar tokens, Twilio tokens, Resend API keys, etc.) are independently encrypted with AES-256-GCM using a master key held outside the database. |
| Encryption in transit | TLS for client ↔ platform and platform ↔ sub-processor connections. |
| Access control | Role-based access in the dashboard, two-factor authentication (TOTP) available for end users, MFA required for Coagentic personnel with production access. |
| Authentication | Hashed passwords (bcrypt, ≥10 rounds), SSO via Google and GitHub OAuth, signed/HTTP-only session cookies. API tokens hashed (SHA-256) at rest; plaintext shown to the user once at creation. |
| Secrets management | Production secrets stored in environment variables managed outside source control; never committed to the repository. |
| Logging and monitoring | Audit log for administrative actions (suspensions, refunds, support impersonation); structured request and error logs. Production error reporting via Sentry when configured. |
| Backups | Encrypted database snapshots; retention policy targeting at least 7 days at launch with the operational target of 30 days as customer load grows. |
| Vulnerability management | Dependency scanning in CI; staging-first rollouts; documented patch SLA (critical < 7 days, high < 30 days). |
| Personnel | Access revoked on offboarding. Background checks and mandatory security training will be implemented as the team grows. |
| Sub-processor due diligence | Security and DPA reviews for each new sub-processor. |
| Incident response | Documented IR runbook for platform incidents; commitment to expand to tabletop exercises and a 24/7 on-call rotation as the team grows. |
| Data deletion | In-product "delete project" + "delete workspace" controls remove user-visible data immediately and purge backups within 30 days. |
Annex B — Approved sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Hetzner | Compute, managed Postgres host volumes, network | EU (Germany / Finland) |
| Cloudflare | CDN, DNS, edge TLS, WAF, transactional email routing | Global edge |
| Polar | Payment processing and subscription billing | US / EU |
| DeepSeek | LLM inference for the AI agent (flash + reasoner models) | Configurable; default endpoint operated by DeepSeek |
| Sentry | Application error monitoring (active when SENTRY_DSN is configured for the deployment) | EU |
The current list at coagentic.work/legal/subprocessors is authoritative.
Third-party services the Controller chooses to connect to its own projects — payment providers (Polar), email providers (Resend), SMS gateways (Twilio), analytics (Google Analytics), object storage (Cloudflare R2) — are processors engaged by the Controller, not sub-processors of Coagentic.
How to execute
The DPA is incorporated into the Agreement automatically upon use of the Services on or after the effective date. Customers required to obtain a counter-signed copy may email [email protected] with their workspace ID; Coagentic will return a signed PDF within 10 business days.
For data-protection inquiries:
- Email: [email protected]
- Postal: Coagentic, attn. data-protection inquiries (postal address provided on request)