Data Processing Agreement
This Data Processing Agreement ("DPA") applies to the processing of Personal Data by Processor on behalf of Controller in connection with the Services. This DPA forms part of, and is incorporated by reference into, the Terms of Service ("Terms"). It is effective from the date the Controller accepts the Terms, and no signature is required for it to be valid and binding on the parties.
1. Parties to this DPA
|
Role |
Entity Details |
|
Data Controller ("Controller") |
The Customer, being the individual or legal entity that has accepted the Terms and registered an account for the Services, as identified by its account registration information. |
|
Data Processor ("Processor") |
Glorium Technologies LTD, Neofytou Nikolaidi & Theodorou Kolokotroni ONISIFOROU CENTER, 2nd floor Agios Theodoros Paphos 8011 Cyprus |
Contacts for Data Protection: Notices to the Processor shall be sent to [email protected]. Notices to the Controller shall be sent to the email address registered in the Controller’s account.
2. Details of Data Processing
|
Subject |
Description |
|
Terms of Service |
This DPA is subject to the Terms of Service between the parties. |
|
Subject Matter |
The subject matter of the processing is the performance of the services as described in the Terms of Service. |
|
Nature and Purpose of Processing |
The Processor will process Personal Data to provide the cloud-based software-as-a-service (SaaS) platform, features, tools, and support as specified in the Terms of Service. |
|
Duration of Processing |
For the term of the Terms of Service, unless otherwise required by applicable law. |
|
Types of Personal Data |
The types of Personal Data processed may include, but are not limited to: • Contact Information: such as name, email address, phone number, and physical address. |
|
Categories of Data Subjects |
The data subjects may include the Controller's employees, customers, vendors, and service providers. |
3. Terms of the DPA
3.1. Definitions
- For the purposes of this DPA, "Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", and "Processor" shall have the meanings ascribed to them in the applicable Data Protection Laws.
- "Data Protection Laws" means all applicable laws and regulations relating to data protection and privacy, including but not limited to the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and any other relevant legislation.
- "Sub-processor" means any third-party processor engaged by the Processor to process Personal Data under this DPA.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as approved by the European Commission.
- "Model Provider" means a third-party entity that develops, hosts, or operates artificial intelligence or machine learning models made available through the Services.
- "Customer-Selected Models" means specific Model Providers that the Controller actively chooses to enable, route data to, or interact with via the configuration settings in the Controller’s account dashboard.
3.2. Obligations of the Parties
- Processor's Obligations: The Processor shall:
- Only process Personal Data on behalf of and in accordance with the Controller's documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do so by law. The Controller's documented instructions are set out in, and comprised of, these Terms, this DPA, and the Controller's configuration and use of the Services; additional or different instructions must be agreed in writing.
- Not sell, retain, or use any Personal Data for any purpose other than as permitted by this DPA and the Terms of Service.
- Ensure that all persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement and maintain the technical and organizational measures specified in Annex 1 to ensure a level of security appropriate to the risk.
- Notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach.
- Provide reasonable assistance to the Controller in responding to requests from Data Subjects exercising their rights under Data Protection Laws.
- Upon termination of the Terms of Service, at the choice of the Controller, delete or return all Personal Data to the Controller, and delete existing copies unless applicable law requires storage of the Personal Data. Notwithstanding the foregoing, to the extent that Personal Data is contained in automated archival or backup systems, the Processor may retain such data in accordance with its standard backup retention and overwrite cycle, provided that such data remains protected in accordance with this DPA, is isolated from active processing, and is eventually destroyed or overwritten in the ordinary course of business.
- The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA. Audits, including inspections, may be conducted by the Controller or an independent auditor mandated by the Controller, at the Controller’s sole cost and expense, subject to reasonable prior written notice, confidentiality obligations, reasonable scope, timing, frequency, and security requirements, and in a manner that does not unreasonably disrupt the Processor’s business operations. Where appropriate, the Processor may satisfy such requests by providing relevant certifications, audit reports, security documentation, questionnaires, summaries, or other equivalent information, and may object to any auditor that is not independent, is a competitor, or does not provide reasonable confidentiality and security assurances.
- Controller's Obligations: The Controller represents and warrants that:
- It has a valid legal basis for the processing of Personal Data by the Processor.
- It has provided all necessary notices and obtained all necessary consents from Data Subjects.
- Its instructions to the Processor for the processing of Personal Data shall comply with all applicable Data Protection Laws.
- It shall not submit to the Services any special category data (as defined in Article 9 GDPR) or other sensitive data (including health, biometric, or genetic data), unless otherwise expressly agreed in writing by the Processor.
3.3. Sub-processing
- The Controller provides a general authorization for the Processor to engage Sub-processors.Where a Sub-processor fails to fulfil its data protection obligations in relation to the Processing, the Processor shall remain liable to the Controller for the performance of those obligations, as required under applicable Data Protection Laws, subject to the limitations and exclusions of liability set forth in the Terms. The Processor's current list of Sub-processors is detailed in Annex 2.
- The Processor shall inform the Controller of any intended addition or replacement of Sub-processors and give the Controller the opportunity to object within fourteen (14) calendar days of such notice. Any objection must be made in writing and based on reasonable, documented grounds relating to data protection. If the Controller does not object within this period, the Sub-processor shall be deemed approved. If the Controller submits a timely objection, the Processor will use commercially reasonable efforts to address the objection or provide an alternative configuration of the affected Services. If no commercially reasonable alternative is available within thirty (30) days, either Party may terminate the affected Services upon written notice as the sole and exclusive remedy, without termination penalty and without prejudice to fees accrued before termination.
- Where the Processor engages a Sub-processor, the Processor shall enter into a written agreement with such Sub-processor imposing data protection obligations that are, in substance, no less protective than those set out in this DPA, to the extent applicable to the nature of the services provided by such Sub-processor.
3.4. Customer-Enabled Third-Party Integrations
For clarity, third-party services or tools that are enabled, connected, or configured by the Controller, including through the Controller’s own account, API key, credentials, tokens, or integration settings, are not considered Sub-processors of the Processor under this DPA, unless the Processor separately engages such third party as its own Sub-processor for the provision of the Services.
Any Personal Data transferred to such third-party services or tools is transferred at the Controller’s instruction and is governed by the Controller’s separate agreement and data protection arrangements with the relevant third party. The Controller is responsible for assessing the lawfulness, security, and data protection compliance of such third-party services or tools.
3.5. Web Search and Web Extraction Features
The Services may allow the Controller and its authorized users to submit search queries, URLs, prompts, or other content for web search, web extraction, retrieval, and further processing.
The Controller is responsible for all information submitted through such features and shall not submit Personal Data, sensitive data, confidential information, or third-party Personal Data unless it has a valid legal basis and all necessary rights, notices, consents, and authorizations.
The Controller acknowledges that such submissions may be transmitted to third-party search, retrieval, or extraction providers engaged by the Processor to provide the relevant functionality. The Controller remains responsible for the content of queries, URLs, prompts, and other materials submitted by the Controller or its authorized users through such features.
3.6. AI Models and Processing
3.6.1. Customer-Selected Models: Where the Services allow the Controller to select specific AI models, model providers, or model configurations through the dashboard, API settings, agent settings, or similar functionality (“Customer-Selected Models”), such selection constitutes the Controller’s instruction to route Customer Data to the selected model or provider for the relevant feature or configuration.
Unless a Customer-Selected Model is clearly identified in the user interface as an external, customer-configured, or non-covered model, Customer-Selected Models made available by the Processor are provided through Processor-approved AI infrastructure providers listed as Sub-processors and used in accordance with this DPA.
Where a Customer-Selected Model is clearly identified in the user interface as external, customer-configured, or not covered by this DPA, the Controller is responsible for reviewing and accepting the applicable provider terms, privacy policies, security practices, and data handling terms before using such model with Personal Data. The Controller may avoid such processing by not selecting, enabling, or using that model.
3.6.2. Core AI Functionality. Core AI functionality is provided only through Processor-approved AI infrastructure providers listed as Sub-processors and subject to the protections set out in this DPA, including Zero Data Retention where available and enabled.
3.6.3. Controller Inputs: Regardless of the model used, the Controller is solely responsible for all information submitted into the models (Inputs), ensuring they have a valid legal basis to process such Personal Data.
3.7. International Data Transfers
- The Processor may transfer Personal Data internationally, provided that any transfer requiring safeguards under applicable Data Protection Laws is protected by an appropriate transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, the UK Addendum, the EU-U.S. Data Privacy Framework, or another valid mechanism, which shall be considered incorporated herein by reference and shall apply, if needed.
3.8. General Provisions
- Order of Precedence: In the event of a conflict regarding the processing of Personal Data, the terms of this DPA shall prevail over the terms of the Terms of Service solely with respect to such processing.
- Governing Law and Jurisdiction: This DPA and any disputes arising from it shall be governed by the laws and jurisdiction stipulated in the Terms of Service.
- Amendments: The Provider may update this DPA in accordance with the "Changes to these Terms" section of the Terms. Any Customer-specific amendment must be agreed in writing by both parties.
4. Incorporation and Acceptance
This DPA is incorporated by reference into the Terms and becomes binding on the parties when the Controller accepts the Terms or uses the Services to process Personal Data. No signature is required for it to be valid and binding on the parties.
ANNEX 1: Security Measures
This Annex describes the technical and organizational security measures implemented by the Processor to protect Personal Data.
1. Infrastructure & Environment
Orchestration: Utilization of container orchestration technologies (e.g., Kubernetes and Helm).
Management: Infrastructure is managed via Infrastructure-as-Code (IaC) principles.
Environment Isolation: Strict logical separation of environments (Development, Staging, and Production).
Data Restrictions: No Customer Personal Data is stored or processed in non-production environments.
2. Data Storage & Protection
Database: Data is stored using secure, cloud-native relational databases (e.g., PostgreSQL).
Encryption in Transit: All data in transit is encrypted using industry-standard protocols (TLS 1.2 or higher).
Data Residency: Customer Personal Data may be processed by the Sub-processors listed in Annex 2 in the locations indicated therein, subject to the transfer safeguards described in Section 3.7.
3. Access & Credential Security
External Integration: Utilization of external integration providers to minimize the storage of credentials.
Encryption at Rest (Credentials): Where storage is strictly required, credentials (such as API keys and OAuth tokens) are encrypted at rest.
Secrets Management: Documented secrets management practices are implemented and enforced.
4. Availability & Resilience
Auto-scaling: Auto-scaling mechanisms are enabled to ensure continued availability during traffic fluctuations.
Load Balancing: Load balancing is utilized to distribute system traffic effectively and maintain stability.
5. Backup & Recovery
Backups: Real-time and continuous database backup procedures are implemented.
Restoration: Backup restoration procedures are regularly tested to ensure data integrity and recoverability.
6. Monitoring & Logging
Observability: Utilization of specialized system monitoring and observability tools.
Logging Capabilities: Comprehensive logging is implemented to support system monitoring, troubleshooting, and audit visibility.
7. Integrations & Data Flow
External Systems: The platform supports integrations with external systems, including CRM, ERP, and other third-party tools, as configured by the Controller.
Data Ingestion: Data may flow into and out of the platform through controlled API endpoints, authentication mechanisms, and integration settings.
Integration Controls: The Processor implements reasonable technical controls for integrations under its control, including access controls, authentication, logging, and secure transmission where applicable.
8. Key Security Principles Enforced
Environment isolation.
Data segregation.
Encryption (in transit for all data, and at rest for credentials).
Controlled data exposure (Principle of Least Privilege).
Continuous operational monitoring.
ANNEX 2: Sub-processors
This Annex lists the Sub-processors authorized by the Controller to process Personal Data.
|
Subprocessor |
Purpose |
Applicable Service |
Location |
|
Pipedream |
Workflow automation and integrations |
Workflows, integrations, webhooks and API connections |
United States |
|
Google Cloud / Vertex AI |
Cloud AI / machine learning processing |
AI processing, prompts, model inputs/outputs, embeddings and related AI workflows |
EU |
|
Mailgun / Sinch Email |
Transactional email delivery |
Service emails |
United States |
|
Stripe |
Payment processing |
Payments and billing |
Global |
|
OVHcloud |
Cloud hosting / infrastructure services |
Hosting infrastructure |
EU / France |
|
Brevo |
Email communications and transactional email delivery |
Email / SMTP / API communications |
EU / France and Belgium |
|
Pipedrive |
Customer relationship management and sales pipeline management |
CRM platform |
Estonia / European Union |
|
HubSpot |
CRM, marketing, sales and customer communications management |
HubSpot customer platform / CRM tools |
Global |
|
PostHog |
Product analytics and feature management |
Analytics, event tracking, session replay, feature flags and related product tools |
EU |
|
Deepgram |
Speech and voice AI processing |
Speech-to-text, text-to-speech, audio intelligence and voice agent APIs |
Global |
|
LiveKit |
Real-time audio/video communications and AI voice infrastructure |
LiveKit Cloud, APIs, agents, media transport, signaling and related services |
EU / France |
|
Composio / Sampark Inc. |
AI agent integrations and tool-call orchestration |
Composio Application Services, including integrations, tool calls, authentication/authorization flows and related support |
United States |
|
OpenRouter |
AI model routing and inference gateway |
API access to third-party AI models, including prompt/completion routing and related services |
United States or other locations depending on selected model providers and configuration |
|
Firecrawl / SideGuide Technologies, Inc. |
Web search and content retrieval for AI agents |
Firecrawl API / web data extraction for AI workflows |
United States |
|
Groq, Inc. |
AI inference and hosted model infrastructure |
GroqCloud API Services, including model inference, prompt/output processing and related support |
United States |
|
Cerebras Systems, Inc. |
AI inference and hosted model infrastructure |
Cerebras Inference Services, including hosted model inference, prompt/output processing and related support |
United States |
|
e2b (FoundryLabs, Inc.) |
AI code execution and sandbox infrastructure |
e2b Sandbox API Services, including secure execution of AI-generated code, code interpreter sessions, prompt/output processing and related support |
United States |
The scope and categories of Customer Personal Data processed by each Subprocessor depend on Customer’s configuration and use of the Services. Each Subprocessor processes Customer Personal Data only as necessary to provide its respective services.
Where applicable, international transfers are protected by Standard Contractual Clauses or other appropriate safeguards.