Data Processing Addendum

Last updated: October 1, 2026

1. Scope and Precedence

1.1 This Data Processing Addendum ("DPA") forms part of the AgentTrail Terms of Service or other written agreement between AgentTrail, Inc. ("AgentTrail") and Customer (the "Agreement"). It applies whenever AgentTrail processes Customer Personal Data in providing the Service.

1.2 If this DPA conflicts with the Agreement, this DPA controls on data protection matters. If this DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses control.

2. Definitions

Capitalized terms not defined here have the meanings given in the Agreement.

  • "Data Protection Laws" means all laws that apply to the processing of Customer Personal Data under the Agreement. These include GDPR, UK GDPR, the Swiss FADP, and the CCPA and other U.S. state privacy laws.
  • "Customer Personal Data" means personal data within Customer Data that AgentTrail processes on Customer's behalf.
  • "Security Incident" means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data.
  • "Subprocessor" means any third party AgentTrail engages to process Customer Personal Data.
  • "Standard Contractual Clauses" or "SCCs" means the clauses approved by European Commission Implementing Decision (EU) 2021/914.
  • "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner.

3. Roles

3.1 Customer is the controller, or a processor acting for its own controllers. AgentTrail is Customer's processor, or subprocessor.

3.2 Customer is responsible for having a lawful basis for the processing, and for giving any notices and obtaining any consents needed for AgentTrail to process Customer Personal Data. That includes notices to employees whose agent sessions are monitored.

3.3 Customer will configure the Service and its Agents to minimize the personal data and secrets sent to the Service.

4. Processing Instructions

4.1 AgentTrail will process Customer Personal Data only on Customer's documented instructions. Those instructions consist of the Agreement, this DPA, and Customer's use and configuration of the Service. The only exception is where the law requires otherwise, in which case AgentTrail will inform Customer first unless the law prohibits it.

4.2 AgentTrail will not:

  • use Customer Personal Data to train or fine-tune machine learning models;
  • sell or share it, as those terms are defined in the CCPA; or
  • combine it with data from other sources, except as needed to provide the Service.

4.3 AgentTrail will tell Customer if it believes an instruction violates Data Protection Laws.

5. Personnel

AgentTrail will make sure that everyone authorized to process Customer Personal Data is bound by confidentiality obligations. Access will be limited to personnel who need it to provide, support, or secure the Service.

6. Subprocessors

6.1 Customer generally authorizes AgentTrail to engage Subprocessors. The current list is in Annex 3 and on our subprocessors page.

6.2 AgentTrail will bind each Subprocessor to written data protection terms at least as protective as this DPA. AgentTrail remains liable for its Subprocessors' performance.

6.3 AgentTrail will give at least 15 days' notice before adding or replacing a Subprocessor, by updating the list and notifying Customer by email. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected Service and receive a refund of prepaid fees for the remaining term.

7. Security

AgentTrail will implement and maintain the technical and organizational measures described in Annex 2. AgentTrail may update those measures, as long as the updates do not materially reduce the overall level of protection.

8. Security Incidents

8.1 AgentTrail will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident.

8.2 The notice will describe, as far as then known:

  • the nature of the incident;
  • the categories and approximate volume of data affected;
  • the likely consequences; and
  • the measures taken or proposed.

AgentTrail will provide updates as it learns more, and will take reasonable steps to contain and remediate the incident.

8.3 Notifying Customer of a Security Incident is not an admission of fault or liability.

9. Assistance

9.1 Data subject requests. AgentTrail will promptly forward to Customer any request from a data subject about Customer Personal Data, and will not respond to it directly except on Customer's instructions. Taking into account the nature of the processing, AgentTrail will provide reasonable assistance so Customer can meet its obligations, including by deleting Customer Personal Data and providing copies of it on Customer's request.

9.2 Assessments. AgentTrail will provide reasonable information to help Customer carry out data protection impact assessments and consult with regulators, where required.

10. Audits

10.1 On written request, and no more than once a year, AgentTrail will provide information to demonstrate its compliance with this DPA. That information may include completed security questionnaires, summaries of its policies, and any third-party audit reports AgentTrail obtains. All of it is AgentTrail's Confidential Information.

10.2 If that information is not enough to demonstrate compliance with Data Protection Laws, Customer may request an audit. Customer must give 30 days' notice. The audit must take place during business hours, be conducted by a mutually agreed independent auditor bound by confidentiality, and be at Customer's expense. A regulator may also require an audit.

11. Return and Deletion

11.1 The Service does not delete Customer Data automatically when a Plan's visibility window passes; older data is hidden, not deleted. While the Agreement is in effect, Customer may ask AgentTrail to delete Customer Personal Data by emailing security@agenttrail.sh from the workspace Owner's address. AgentTrail will delete it within 30 days of the request.

11.2 After termination, Customer has 30 days to request a copy of its Customer Data. AgentTrail will then delete Customer Personal Data within 30 days. Copies in automated database backups expire within a further 30 days. The only exception is data AgentTrail must retain by law, which it will keep protected under this DPA and not otherwise process. On request, AgentTrail will confirm deletion in writing.

12. International Transfers

12.1 AgentTrail processes Customer Personal Data in the United States (Amazon Web Services, us-east-1), and its Subprocessors process it in the locations listed in Annex 3. When Customer Personal Data is transferred from the EEA to a country without an adequacy decision, the SCCs are incorporated by reference, as follows:

  • Module 2 (controller to processor) applies where Customer is a controller, and Module 3 (processor to processor) applies where Customer is a processor.
  • Clause 7 (docking) applies.
  • Under Clause 9(a), Option 2 (general authorization) applies, with the notice period in Section 6.3.
  • The optional wording in Clause 11 does not apply.
  • Under Clauses 17 and 18, the governing law and courts are those of Ireland.
  • Annexes I and II of the SCCs are completed by Annexes 1 and 2 of this DPA.

12.2 For transfers from the UK, the UK Addendum applies, with Table 1 through Table 3 completed using this DPA's details. For transfers from Switzerland, the SCCs apply with references read as references to the FADP, and the competent authority is the FDPIC.

12.3 If a transfer mechanism is invalidated, the parties will cooperate in good faith to put an alternative in place.

13. U.S. State Privacy Laws

Where the CCPA or similar U.S. state laws apply, AgentTrail is a "service provider" or "processor." AgentTrail will not:

  • sell or share Customer Personal Data;
  • retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship between the parties; or
  • combine it with personal data from other sources, except as those laws permit.

AgentTrail certifies that it understands these restrictions. It will notify Customer if it can no longer meet its obligations, and Customer may then take reasonable steps to stop and remediate unauthorized use.

14. Liability and General

Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement. This DPA remains in effect for as long as AgentTrail processes Customer Personal Data. Any update to Data Protection Laws that requires changes to this DPA will be handled by good-faith amendment.

Annex 1: Description of Processing

ItemDescription
Data exporterCustomer, as identified in the Agreement or account
Data importerAgentTrail, Inc., 420 Jackson Avenue, Dunellen, NJ 08812; contact privacy@agenttrail.sh
Data subjectsCustomer's Users (developers and administrators), and any individuals whose personal data appears in code, prompts, commits, or files that Customer's Agents access
Categories of dataUser names, emails, and identifiers; device and IP data; agent session telemetry (prompts, tool calls, commands, file paths, code snippets, diffs, outputs, timestamps), which may incidentally contain other personal data
Sensitive dataNot intended. Customer must not submit special-category data. Any that appears incidentally is protected by the measures in Annex 2
Nature and purposeCollecting, storing, analyzing, and displaying agent activity so that Customer can observe, audit, and enforce policies on its AI agents
FrequencyContinuous, while Agents are connected
RetentionKept until Customer requests deletion or the Agreement ends, then deleted as described in Section 11. The Plan's visibility window limits what Customer can see, not what is stored

Annex 2: Technical and Organizational Measures

  • Encryption: TLS 1.2 or higher for connections to the web application and API. Encryption at rest for the application database, the trace database's storage volume, file storage, and job queues.
  • Access control: role-based access within each workspace; API keys scoped to a single organization; passwords stored only as one-way hashes. Production deployments run through an automated pipeline with a manual approval step.
  • Tenant isolation: all customers share infrastructure. Each organization's data is kept separate by organization-scoped queries in the application and by row-level security in the application database.
  • Secret scrubbing: before storage, pattern-based scrubbing removes common credential and personal-data formats, such as cloud provider keys, access tokens, JWTs, private keys, connection strings, email addresses, and payment card and Social Security numbers. Scrubbing is best-effort and does not catch every secret.
  • Logging and monitoring: an audit log of administrative actions in the Service, a web application firewall in front of the web application and API, and error monitoring with IP addresses removed.
  • Secure development: code review for all changes, vulnerability scanning of container images that blocks releases with critical findings, and infrastructure as code.
  • Resilience: a multi-zone application database with automated backups kept for 30 days, and hourly snapshots of the trace database to encrypted storage.
  • Personnel: confidentiality obligations for everyone with access to Customer Personal Data, and access limited to those who need it.

Annex 3: Subprocessors

SubprocessorPurposeLocation
Amazon Web Services, Inc.Cloud hosting and storage for all Customer DataUnited States (us-east-1)
Amazon Web Services, Inc. (SES)Transactional email: recipient address and message contentUnited States (us-east-1)
Upstash, Inc.Managed Redis: sign-in tokens, rate limits, and a short buffer of recent live updatesUnited States (us-east-1)
Anthropic, PBCAI classification, rule drafting, and pattern review, on the limited excerpts described on our subprocessors pageUnited States
Functional Software, Inc. (Sentry)Error and performance monitoring, with IP addresses removedUnited States
WorkOS, Inc.Sign-in with Google or GitHub: name, email address, and account identifierUnited States
Vercel Inc.Hosting for the web application: page requests, not trace dataUnited States
Stripe, Inc.Payment processing: billing contact, payment card, subscription and usage totalsUnited States