Data Processing Agreement


This Data Processing Agreement ("DPA") applies to the processing of Personal Data by Processor on behalf of Controller in connection with the Services. This DPA forms part of, and is incorporated by reference into, the Terms of Service ("Terms"). It is effective from the date the Controller accepts the Terms, and no signature is required for it to be valid and binding on the parties. 

1. Parties to this DPA 

Role

Entity Details

Data Controller ("Controller")

The Customer, being the individual or legal entity that has accepted the Terms and registered an account for the Services, as identified by its account registration information.

Data Processor ("Processor")

Glorium Technologies LTD, Neofytou Nikolaidi & Theodorou Kolokotroni ONISIFOROU CENTER, 2nd floor Agios Theodoros Paphos 8011 Cyprus

Contacts for Data Protection: Notices to the Processor shall be sent to [email protected]. Notices to the Controller shall be sent to the email address registered in the Controller’s account. 

2. Details of Data Processing

Subject

Description

Terms of Service

This DPA is subject to the Terms of Service between the parties. 

Subject Matter

The subject matter of the processing is the performance of the services as described in the Terms of Service.

Nature and Purpose of Processing

The Processor will process Personal Data to provide the cloud-based software-as-a-service (SaaS) platform, features, tools, and support as specified in the Terms of Service.

Duration of Processing

For the term of the Terms of Service, unless otherwise required by applicable law.

Types of Personal Data

The types of Personal Data processed may include, but are not limited to:

 • Contact Information: such as name, email address, phone number, and physical address.
Technical Information: such as IP addresses, browser type, device information, cookies, and usage data.
Professional Information: such as job title, company name, and professional contact details.
Financial Information: such as billing details and payment information.
User-Generated Content: any personal data provided by the user in the course of using the services.

Categories of Data Subjects

The data subjects may include the Controller's employees, customers, vendors, and service providers.

3. Terms of the DPA 

3.1. Definitions

3.2. Obligations of the Parties

3.3. Sub-processing

3.4. Customer-Enabled Third-Party Integrations

For clarity, third-party services or tools that are enabled, connected, or configured by the Controller, including through the Controller’s own account, API key, credentials, tokens, or integration settings, are not considered Sub-processors of the Processor under this DPA, unless the Processor separately engages such third party as its own Sub-processor for the provision of the Services.

Any Personal Data transferred to such third-party services or tools is transferred at the Controller’s instruction and is governed by the Controller’s separate agreement and data protection arrangements with the relevant third party. The Controller is responsible for assessing the lawfulness, security, and data protection compliance of such third-party services or tools.

3.5. Web Search and Web Extraction Features

The Services may allow the Controller and its authorized users to submit search queries, URLs, prompts, or other content for web search, web extraction, retrieval, and further processing.

The Controller is responsible for all information submitted through such features and shall not submit Personal Data, sensitive data, confidential information, or third-party Personal Data unless it has a valid legal basis and all necessary rights, notices, consents, and authorizations.

The Controller acknowledges that such submissions may be transmitted to third-party search, retrieval, or extraction providers engaged by the Processor to provide the relevant functionality. The Controller remains responsible for the content of queries, URLs, prompts, and other materials submitted by the Controller or its authorized users through such features. 

3.6. AI Models and Processing 

3.6.1. Customer-Selected Models: Where the Services allow the Controller to select specific AI models, model providers, or model configurations through the dashboard, API settings, agent settings, or similar functionality (“Customer-Selected Models”), such selection constitutes the Controller’s instruction to route Customer Data to the selected model or provider for the relevant feature or configuration.

Unless a Customer-Selected Model is clearly identified in the user interface as an external, customer-configured, or non-covered model, Customer-Selected Models made available by the Processor are provided through Processor-approved AI infrastructure providers listed as Sub-processors and used in accordance with this DPA.

Where a Customer-Selected Model is clearly identified in the user interface as external, customer-configured, or not covered by this DPA, the Controller is responsible for reviewing and accepting the applicable provider terms, privacy policies, security practices, and data handling terms before using such model with Personal Data. The Controller may avoid such processing by not selecting, enabling, or using that model. 

3.6.2. Core AI Functionality. Core AI functionality is provided only through Processor-approved AI infrastructure providers listed as Sub-processors and subject to the protections set out in this DPA, including Zero Data Retention where available and enabled.  

3.6.3. Controller Inputs: Regardless of the model used, the Controller is solely responsible for all information submitted into the models (Inputs), ensuring they have a valid legal basis to process such Personal Data.

3.7. International Data Transfers

3.8. General Provisions

4. Incorporation and Acceptance 

This DPA is incorporated by reference into the Terms and becomes binding on the parties when the Controller accepts the Terms or uses the Services to process Personal Data. No signature is required for it to be valid and binding on the parties.   


ANNEX 1: Security Measures

This Annex describes the technical and organizational security measures implemented by the Processor to protect Personal Data.

1. Infrastructure & Environment

2. Data Storage & Protection

3. Access & Credential Security

4. Availability & Resilience

5. Backup & Recovery

6. Monitoring & Logging

7. Integrations & Data Flow

8. Key Security Principles Enforced

ANNEX 2: Sub-processors

This Annex lists the Sub-processors authorized by the Controller to process Personal Data.


Subprocessor

Purpose 

Applicable Service 

Location 

Pipedream

Workflow automation and integrations 

Workflows, integrations, webhooks and API connections  

United States  

Google Cloud / Vertex AI 

Cloud AI / machine learning processing  

AI processing, prompts, model inputs/outputs, embeddings and related AI workflows 

EU

Mailgun / Sinch Email 

Transactional email delivery 

Service emails 

United States 

Stripe 

Payment processing

Payments and billing  

Global 

OVHcloud 

Cloud hosting / infrastructure services

Hosting infrastructure 

EU / France

Brevo 

Email communications and transactional email delivery 

Email / SMTP / API communications 

EU / France and Belgium 

Pipedrive 

Customer relationship management and sales pipeline management 

CRM platform 

Estonia / European Union 

HubSpot 

CRM, marketing, sales and customer communications management 

HubSpot customer platform / CRM tools 

Global

PostHog 

Product analytics and feature management 

Analytics, event tracking, session replay, feature flags and related product tools 

EU 

Deepgram 

Speech and voice AI processing 

Speech-to-text, text-to-speech, audio intelligence and voice agent APIs 

Global 

LiveKit 

Real-time audio/video communications and AI voice infrastructure 

LiveKit Cloud, APIs, agents, media transport, signaling and related services 

EU / France

Composio / Sampark Inc. 

AI agent integrations and tool-call orchestration 

Composio Application Services, including integrations, tool calls, authentication/authorization flows and related support 

United States 

OpenRouter 

AI model routing and inference gateway 

API access to third-party AI models, including prompt/completion routing and related services  

United States or other locations depending on selected model providers and configuration 

Firecrawl / SideGuide Technologies, Inc. 

Web search and content retrieval for AI agents 

Firecrawl API / web data extraction for AI workflows 

United States 

Groq, Inc. 

AI inference and hosted model infrastructure 

GroqCloud API Services, including model inference, prompt/output processing and related support 

United States 

Cerebras Systems, Inc. 

AI inference and hosted model infrastructure 

Cerebras Inference Services, including hosted model inference, prompt/output processing and related support 

United States

e2b (FoundryLabs, Inc.)

AI code execution and sandbox infrastructure

e2b Sandbox API Services, including secure execution of AI-generated code, code interpreter sessions, prompt/output processing and related support

United States

The scope and categories of Customer Personal Data processed by each Subprocessor depend on Customer’s configuration and use of the Services. Each Subprocessor processes Customer Personal Data only as necessary to provide its respective services.

Where applicable, international transfers are protected by Standard Contractual Clauses or other appropriate safeguards.