Legal / Data Processing Agreement

Data Processing Agreement

Annex B to the Service Agreement · draft — not yet reviewed by a lawyer

This is a template, not a signed contract. It shows the GDPR article 28 terms that come with every Service Agreement, with client-specific fields left as placeholders. It has not yet been reviewed by a lawyer. The version you actually sign is confirmed with you during the intake call.

Between [the Client] (the Controller) and DSNS, sole proprietorship of Seth Desaunois, KvK 97704172 (the Processor). This agreement is written to satisfy article 28(3) GDPR and takes effect on the same date as the Service Agreement it belongs to.

Where this agreement and the Service Agreement disagree about personal data, this one wins.

01What is processed, and why

Subject matterRunning software agents that carry out work inside the Controller's business
PurposeOnly to deliver what Annex A of the Service Agreement describes. Nothing else
DurationFor as long as the Service Agreement runs, plus the handover period in clause 9
Nature of processingReading, classifying, drafting, storing, and — only where the Controller has switched a category to unattended — sending

Categories of data subjects: the Controller's customers; people who contact the Controller; the Controller's own staff whose names appear in the correspondence.

Types of personal data: name, email address, postal address, phone number, order number and order history, and the free text of messages. That last one is the widest category: a customer can put anything in an email, so the content of a message may hold more than the fields above.

No special-category data is asked for and none is needed. Where a customer volunteers it in a message, it is processed only as part of that message, and never used to make an automated decision about them.

02The Controller instructs, the Processor follows

The Processor processes personal data only on the Controller's documented instructions. This agreement, the Service Agreement and Annex A are those instructions; anything further is agreed in writing.

The Processor tells the Controller if an instruction appears to breach the GDPR or Dutch implementing law, and may pause that instruction until it is resolved.

The Processor does not use the data for its own purposes. Specifically, and this is a commitment, not a description of current practice: no client's data is pooled with another client's, averaged across clients, or used to train a model. Each business runs on its own machine with its own configuration file.

03Confidentiality

Access to the data is limited to those who need it to run the service, and everyone the Processor allows near it is bound to confidentiality before they get access. Today that access sits with Seth Desaunois, who builds and maintains the system — a named person the Controller can reach directly, and the smallest access surface this arrangement can have.

04Security (article 32)

The measures below are in place and are the ones the Controller is entitled to hold the Processor to. They may be improved; they are not reduced without written agreement.

Separation. Each client's agents run on a server rented for that client alone. No other business runs on that machine, and no other business's configuration is reachable from it.

Access. Password logins to the server are switched off; access is by key only. A firewall allows only the ports needed to run the service. Automatic security updates are enabled, and repeated failed login attempts are blocked automatically.

In transit. All traffic to and from the server runs over an encrypted connection. Credentials are never sent in readable form.

What an agent is allowed to do. Every action an agent attempts passes through one function before anything happens. Reading is allowed; anything that changes or sends is refused unless it is written down by name in a file that a person reviewed and put under version control. A tool whose action cannot be determined from its name is refused for that reason alone. The default is no.

Nothing is inherited. An agent starts with no context beyond four files it is handed explicitly: its own instructions, the Controller's business profile, its tool list and its permitted skills. It picks up nothing from the environment it happens to run in.

Logging. Each run records what it did, what it cost and what it changed, so that any output can be traced back to the input that produced it.

Restoring. The configuration and code needed to rebuild an instance are held in version control outside that instance, so a lost server can be rebuilt rather than recovered.

05Sub-processors

The Controller gives general written authorisation for the sub-processors listed below. The Processor tells the Controller in writing at least 14 days before adding or replacing one, and the Controller may object on reasonable data-protection grounds — in which case the parties look for a workable alternative, and if there is none, the Controller may end the Service Agreement without notice cost.

PartyWhat it doesWhere
Hetzner Online GmbHHosts the server the agents run onGermany (EU)
Anthropic PBCProvides the model that reads and draftsUnited States
ComposioProvides the authorised connections to the mailbox, shop and ad accountsUnited States

A distinction worth stating plainly: the accounts with these parties are held and paid for by the Controller directly (Service Agreement clause 2), so the contract with each of them is in the Controller's own name. The Processor selects and configures them, and lists them here regardless, because the question the Controller actually needs answered is who touches their data — not who signs the invoice.

Transfers outside the EU. Two of the three are established in the United States. Those transfers rest on the European Commission's standard contractual clauses as included in each provider's own data processing terms, which the Controller accepts when opening the account. [Confirmed with the current terms of both providers at intake].

06Helping the Controller with data subject rights

Where someone asks for access, correction, deletion, restriction, portability, or objects to processing, the Processor:

  • passes any request it receives directly to the Controller within two working days, and does not answer it itself;
  • helps the Controller answer it, taking into account the nature of the processing and the information available to the Processor.

Because a message may be spread over the mailbox, the run log and the business profile, the Processor will locate and act on all three when asked, not just the mailbox.

07Helping with security and breaches (articles 32-36)

The Processor helps the Controller meet its own obligations on security, breach notification, impact assessments and prior consultation, to the extent the Controller depends on the Processor for it.

On a personal data breach, the Processor notifies the Controller without undue delay and in any event within 24 hours of becoming aware, with what is known at that moment: what happened, when, which categories and roughly how many people and records are involved, the likely consequences, and what is being done. Later facts follow as they come in. The Processor does not wait for a complete picture before the first message.

08Audit and information

The Processor makes available the information needed to show that this agreement is being met, and allows audits or inspections by the Controller or an auditor it appoints, once per calendar year and on 14 days' notice, or sooner after a breach. An audit may not compromise another client's data. The Controller bears the cost of an audit it initiates, unless the audit finds a material failure.

09What happens at the end

Within 14 days of the Service Agreement ending, at the Controller's choice:

  • Return. The Processor hands over an export of the personal data it holds in a readable format; or
  • Deletion. The Processor deletes it.

Either way, the Processor deletes remaining copies within 30 days and confirms in writing when it is done — unless EU or member state law requires it to be kept, in which case the Processor says which law and for how long.

The server itself is the Controller's own. What stands on it after the handover is the Controller's responsibility.

10Liability

The liability provisions of the Service Agreement apply to this agreement too, except where mandatory law says otherwise. Nothing here limits a data subject's rights or the supervisory authority's powers.

—Signed, with the Service Agreement

DSNS (Processor)The Client (Controller)
Name: Seth DesaunoisName: [filled in at intake]
Date:Date:
Signature:Signature: