Skip to main content

Legal

Data Processing Agreement

Version 1.1 — Effective 2026-05-10 · Back to summary

This Data Processing Agreement ("DPA") forms part of the Coagentic Terms of Service or any equivalent master services agreement (the "Agreement") between Coagentic ("Processor") and the customer ("Controller") that subscribes to the Coagentic platform.

When applicable law (including the EU GDPR, UK GDPR, Swiss FADP, California CCPA/CPRA, and Türkiye's KVKK) requires a written contract for the processing of Personal Data, this DPA governs the parties' obligations.

By using the Coagentic platform on or after the effective date above, the Controller agrees to this DPA.

1. Definitions

  • Controller, Processor, Sub-processor, Personal Data, Data Subject, Process / Processing, and Personal Data Breach have the meanings given to them in the GDPR.
  • Customer Data means data the Controller (and its end users) submits to the Coagentic platform.
  • Services means the Coagentic SaaS platform and any related professional services.
  • Standard Contractual Clauses (SCCs) means the European Commission's Standard Contractual Clauses adopted under Decision 2021/914 of 4 June 2021.

2. Subject matter, duration, nature and purpose

Subject matterProvision of the Services as described in the Agreement.
DurationFor the term of the Agreement, plus any post-termination retention period agreed below.
Nature and purposeHosting Customer Data; running AI models on prompts the Controller submits; storing and indexing project files, databases, conversations, integrations, and analytics.
Type of Personal DataNames, email addresses, profile photos, IP addresses, device/usage telemetry, AI prompts and responses, content the Controller chooses to upload, payment metadata (handled exclusively by Polar).
Categories of Data SubjectsController's authorised users, employees, contractors, end customers, prospects, and any other individuals whose data the Controller chooses to process via the Services.

The Processor will not process Personal Data for any other purpose unless required by law.

3. Processor obligations

The Processor will:

  1. Process only on documented instructions. The Agreement, this DPA, and lawful in-product configuration constitute the Controller's documented instructions. If the Processor believes an instruction violates applicable law, it will inform the Controller without delay.
  2. Confidentiality. Ensure that personnel authorised to process Personal Data are bound by appropriate confidentiality obligations.
  3. Security. Implement and maintain the technical and organisational measures described in Annex A.
  4. Sub-processors. Engage sub-processors only as set out in §6.
  5. Assist the Controller. Provide reasonable assistance with data subject requests, DPIAs, and prior consultations with supervisory authorities (Articles 32–36 GDPR).
  6. Personal Data Breach. Notify the Controller without undue delay (and in any event within 72 hours after becoming aware) of any Personal Data Breach involving Customer Data, providing the information required under Article 33(3) GDPR.
  7. End of services. Upon termination, delete or return all Customer Data within 30 days unless retention is required by applicable law.
  8. Audits. Once per 12-month period, the Controller may, with at least 30 days' written notice, request an audit limited to information required to verify compliance with this DPA. The audit may be satisfied by the Processor providing a then-current third-party audit report (e.g. SOC 2 Type II) or equivalent certification once available.

4. Controller obligations

The Controller will:

  1. Lawful basis. Establish and maintain a lawful basis for the Processor's processing of Customer Data on its behalf.
  2. Notice and consent. Provide all required notices and obtain all necessary consents from Data Subjects before submitting Personal Data to the Services.
  3. Configuration. Configure the Services (e.g. data retention windows, integrations, sub-processor regions) consistently with its compliance obligations.
  4. Lawful instructions. Issue instructions that comply with applicable data-protection law.

5. Data subject rights

The Processor will, taking into account the nature of the processing, assist the Controller by providing in-product tools (export, deletion, restriction) and, where those tools are insufficient, by providing reasonable assistance with responding to requests from Data Subjects exercising rights under Articles 12–22 GDPR (or equivalent local law).

If the Processor receives a Data Subject request directly, it will, unless legally prohibited, inform the Data Subject to contact the Controller and notify the Controller without undue delay.

6. Sub-processors

The Controller grants a general authorisation to engage the sub-processors listed in Annex B. The Processor will:

  1. Maintain an up-to-date list of sub-processors at coagentic.work/legal/subprocessors.
  2. Notify the Controller (via in-product notice or email) at least 14 days before adding or replacing a sub-processor.
  3. Impose obligations on each sub-processor that are no less protective than this DPA.
  4. Remain liable for the acts and omissions of each sub-processor.

The Controller may object to a new sub-processor on reasonable data-protection grounds within 14 days of notice. If the parties cannot resolve the objection in good faith, the Controller may terminate the affected portion of the Services and receive a pro-rata refund of pre-paid fees.

Third-party services the Controller chooses to connect to its own projects (e.g. payment providers, email providers, SMS gateways, analytics) are processors engaged by the Controller, not sub-processors of Coagentic. The Controller is responsible for executing any required agreements with those providers directly.

7. International transfers

Where the Services involve transfers of Personal Data from the EEA, UK, or Switzerland to a country that the European Commission (or applicable authority) has not deemed to provide adequate protection, the parties agree that:

  1. The EU SCCs (Module Two — Controller to Processor) are incorporated by reference, with: Clause 7 ("docking") enabled; Clause 9(a) Option 2 (general authorisation, with the notice period in §6.2 above); Clause 11(a) — independent dispute-resolution body not added; Clause 17 — governing law: Ireland; Clause 18 — competent court: Dublin, Ireland; Annex I.A populated with the parties' identities (taken from the Agreement); Annex I.B populated by §2 of this DPA; Annex I.C — supervisory authority of the EEA member state of the Controller; Annex II populated by Annex A of this DPA.
  2. For UK transfers, the UK International Data Transfer Addendum (issued by the ICO) is incorporated, with the EU SCCs above as the approved transfer mechanism.
  3. For Swiss transfers, references to the GDPR are read as references to the FADP, references to "EU" / "Member State" include Switzerland, and the FDPIC is the competent supervisory authority.

8. CCPA / CPRA addendum (California)

To the extent the Processor processes "personal information" of California residents on behalf of the Controller within the meaning of the CCPA/CPRA, the Processor:

  1. Acts as a service provider (or contractor where applicable);
  2. Will not sell or share personal information;
  3. Will not retain, use, or disclose personal information outside the direct business relationship between the parties or for any purpose other than the business purposes specified in the Agreement;
  4. Certifies that it understands the restrictions in this section.

9. KVKK addendum (Türkiye)

Where the Controller is established in Türkiye or processes data of individuals in Türkiye and KVKK applies:

  1. The Controller is the "veri sorumlusu" and the Processor is the "veri işleyen".
  2. Cross-border transfers comply with Article 9 KVKK; the Controller is responsible for any explicit consents required.
  3. The technical and organisational measures in Annex A satisfy the KVKK Authority's published guidance on data security.

10. Liability

The parties' aggregate liability under this DPA is subject to the limitations of liability in the Agreement.

11. Conflict and order of precedence

In case of conflict, the order of precedence is: (i) the SCCs / UK Addendum where applicable, (ii) this DPA, (iii) the Agreement.

12. Changes

The Processor may update this DPA to reflect changes in applicable law or platform architecture. Material changes will be communicated to the Controller's billing-contact email address and posted at coagentic.work/legal/dpa.


Annex A — Technical and organisational measures

Network securityAll traffic served via HTTPS (TLS 1.2+); HSTS enabled on platform domains. WAF and rate-limiting at the edge (Cloudflare).
Encryption at restPostgres volumes are encrypted at the disk layer by the hosting provider. Integration credentials (Polar tokens, Twilio tokens, Resend API keys, etc.) are independently encrypted with AES-256-GCM using a master key held outside the database.
Encryption in transitTLS for client ↔ platform and platform ↔ sub-processor connections.
Access controlRole-based access in the dashboard, two-factor authentication (TOTP) available for end users, MFA required for Coagentic personnel with production access.
AuthenticationHashed passwords (bcrypt, ≥10 rounds), SSO via Google and GitHub OAuth, signed/HTTP-only session cookies. API tokens hashed (SHA-256) at rest; plaintext shown to the user once at creation.
Secrets managementProduction secrets stored in environment variables managed outside source control; never committed to the repository.
Logging and monitoringAudit log for administrative actions (suspensions, refunds, support impersonation); structured request and error logs. Production error reporting via Sentry when configured.
BackupsEncrypted database snapshots; retention policy targeting at least 7 days at launch with the operational target of 30 days as customer load grows.
Vulnerability managementDependency scanning in CI; staging-first rollouts; documented patch SLA (critical < 7 days, high < 30 days).
PersonnelAccess revoked on offboarding. Background checks and mandatory security training will be implemented as the team grows.
Sub-processor due diligenceSecurity and DPA reviews for each new sub-processor.
Incident responseDocumented IR runbook for platform incidents; commitment to expand to tabletop exercises and a 24/7 on-call rotation as the team grows.
Data deletionIn-product "delete project" + "delete workspace" controls remove user-visible data immediately and purge backups within 30 days.

Annex B — Approved sub-processors

Sub-processorPurposeRegion
HetznerCompute, managed Postgres host volumes, networkEU (Germany / Finland)
CloudflareCDN, DNS, edge TLS, WAF, transactional email routingGlobal edge
PolarPayment processing and subscription billingUS / EU
DeepSeekLLM inference for the AI agent (flash + reasoner models)Configurable; default endpoint operated by DeepSeek
SentryApplication error monitoring (active when SENTRY_DSN is configured for the deployment)EU

The current list at coagentic.work/legal/subprocessors is authoritative.

Third-party services the Controller chooses to connect to its own projects — payment providers (Polar), email providers (Resend), SMS gateways (Twilio), analytics (Google Analytics), object storage (Cloudflare R2) — are processors engaged by the Controller, not sub-processors of Coagentic.


How to execute

The DPA is incorporated into the Agreement automatically upon use of the Services on or after the effective date. Customers required to obtain a counter-signed copy may email [email protected] with their workspace ID; Coagentic will return a signed PDF within 10 business days.

For data-protection inquiries:

  • Email: [email protected]
  • Postal: Coagentic, attn. data-protection inquiries (postal address provided on request)