Skip to main content

    DPA Template

    Beta B2B DPA (GDPR Art. 28): Controller vs Processor, subprocessors with repo evidence, Art. 32 TOMs annex, transfers, deletion targets, and implementation gaps checklist. Markdown download available.

    Legal Notices — all published notices in one place.

    Effective date: 2026-08-16 · Last updated: 2026-08-16

    Download publication-ready DPA (Markdown)

    Agent Smith — Data Processing Addendum (beta template)

    This Data Processing Addendum ("DPA") supplements the agreement under which the Customer uses Agent Smith. It reflects the roles under the EU/UK GDPR: the Customer (as workspace owner) is the Controller for personal data the Customer uploads or causes to be processed in workspaces; Alessandro Scire Calabrisotto, sole proprietor (registered firm The Swiss Standard by Alessandro Scire Calabrisotto), operating Agent Smith ("Processor") processes that data on the Customer's instructions to provide the Service, as described in GDPR Article 28.

    Processor address: Seebahnstrasse 121, 8003 Zürich, Switzerland. Contact: support@agentsmith.ch (operational / privacy requests), legal@agentsmith.ch (legal notices).

    1. Processing details (Art. 28(3) schedule)

    • Subject matter: Hosting, storage, and processing of personal data that the Customer (or users the Customer authorizes) submits to the Service within workspaces.
    • Duration: For the term of the Customer's subscription or use of the Service, plus a limited period thereafter to complete deletion, backups, and legal obligations, as described in the Privacy Policy and this DPA.
    • Nature and purpose: Cloud software services: collaboration, document and message handling, AI-assisted features the Customer enables, integrations the Customer connects, authentication, security, abuse prevention, and support.
    • Type of personal data: Identifiers and contact data, account and profile data, employment/HR-like data the Customer chooses to store, communications, file content, usage metadata, billing-related identifiers, OAuth connection metadata, and AI prompts/outputs where those features are used.
    • Categories of data subjects: The Customer's personnel, contractors, clients, end users, or any other individuals whose personal data the Customer uploads or integrates.

    Instructions: The Customer's configuration and use of the Service (including workspace settings, invites, integrations, and AI options) constitute documented instructions unless otherwise agreed in writing. Processor will not process personal data for incompatible purposes unless required by EU or Member State law (in which case Processor will inform the Customer unless prohibited).

    AI routing privacy control: For non-free text models sent through OpenRouter, Processor requests Zero Data Retention (ZDR) and denies provider data collection using data_collection=deny. OpenRouter may use only endpoints that declare those controls. Nemotron Free is an explicit exception: its upstream terms state that inputs may be logged and used for NVIDIA product improvement. A direct-provider fallback is outside the OpenRouter ZDR request and follows that provider's API terms and the applicable agreement. The Customer must not treat every AI route as ZDR.

    2. Subprocessors

    The Customer authorizes Processor to engage the subprocessors reasonably required to provide the Service. The public list is maintained at Subprocessor List. The table below adds status and indicative evidence (repo paths for internal verification; not a warranty of completeness).

    SubprocessorFunctionStatusIndicative evidence (repo)
    SupabaseAuth, database, storage, edge functionsActive (core)supabase/, src/integrations/supabase/
    VercelApplication hosting, CDN, edge routingActive (core)Hosting platform — infrastructure-level, no in-repo evidence path
    StripePayments, subscriptionsActivesupabase/functions/stripe-*, src/pages/account/AccountBillingPage.tsx
    ResendTransactional email (invites, notices)Active / optional (env)supabase/functions/*
    SentryError monitoringOptionalEnv-gated SDK if present — confirm per environment
    OpenAIAI inferenceActivesupabase/functions/_shared/ai/modelRouting.ts
    AnthropicAI inferenceActivesupabase/functions/_shared/ai/modelRouting.ts
    Google (Gemini)AI inferenceActivesupabase/functions/_shared/ai/modelRouting.ts
    xAI (Grok)AI inferenceActivesupabase/functions/_shared/ai/modelRouting.ts
    OpenRouterPrimary AI model routing and aggregation across inference endpointsActive (primary text route)supabase/functions/_shared/ai/llmCascade.ts
    NVIDIANemotron model inference and Free-route model improvementActive (Nemotron model; Free route has separate data terms)supabase/functions/_shared/ai/llmCascade.ts
    DeepSeekDeepSeek model inference through OpenRouter endpointsActive (model-dependent)supabase/functions/_shared/ai/llmCascade.ts
    BrowserbaseManaged cloud browser runtime for agent browser-automation actionsOptional (env-gated; active only when the browser runtime is provisioned)supabase/functions/execute-browser-action/, supabase/functions/browser-auth-onboarding-start/
    Captcha (hCaptcha / Turnstile)Abuse preventionOptional (env)Frontend / edge integration when enabled
    Connected integrationsUser-enabled integrationsUser-enabledOAuth token storage patterns in DB — verify encryption at rest for your deployment

    Processor will impose data protection terms on subprocessors that are materially consistent with this DPA. The Customer may object to new or replacement subprocessors on reasonable grounds; where no alternative exists, either party may terminate the affected Service components as described in the main agreement.

    3. Technical and organizational measures (Art. 32)

    Processor implements technical and organizational measures ("TOMs") appropriate to the risk, including as regards confidentiality, integrity, availability, and resilience. The following annex maps high-level controls to indicative implementation in the product stack. It does not replace a penetration test report or ISO certificate.

    Measure (Art. 32)SummaryIndicative evidence (repo)
    Access control & segregationAuthenticated access; workspace-scoped data access patterns in the application and database layer.supabase/migrations/*.sql (RLS policies), app routes under src/pages/platform/
    Object storage restrictionsStorage buckets for uploads/avatars/docs with policies aligned to workspace membership.supabase/migrations/*bucket*.sql
    AuthenticationEmail magic link / OTP via Supabase Auth.src/lib/supabaseClient.ts, auth pages under src/pages/auth/
    Transport securityTLS for client–server and HTTPS APIs.Standard deployment / Supabase hosted endpoints
    Secrets & integration tokensOAuth and integration credentials stored with platform-appropriate protection; review encryption-at-rest for tokens in your deployment.Integration storage in DB — verify column-level encryption or KMS in production config (see gaps below).
    Abuse preventionRate limits, optional captcha, invite/share controls.Edge functions, supabase/functions/invite-lookup/, share link flows
    Retention & deletionAccount/workspace deletion flows; scheduled jobs for some AI-related data; target to complete deletion within ~30 days subject to legal hold and operational constraints.supabase/functions/delete-account/, AI chat migrations / jobs — full matrix not proven in repo (see gaps).

    4. International transfers (Chapter V / Art. 44+)

    Processor is established in Switzerland. The European Commission has adopted an adequacy decision for Switzerland in relevant configurations, which can support transfers from the EEA without additional safeguards in many cases. Where subprocessors process personal data outside the EEA/CH, Processor will use appropriate safeguards (e.g. Standard Contractual Clauses) or other lawful mechanisms as required.

    5. Confidentiality; personnel

    Processor ensures that persons authorized to process personal data are bound by appropriate confidentiality obligations.

    6. Security incidents

    Processor will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data in Processor's control, where such notification is required by applicable law, and will provide information reasonably available to assist the Customer in meeting Controller obligations.

    7. Assistance (data subjects & DPIA)

    Taking into account the nature of processing, Processor will assist the Customer—by appropriate technical and organizational measures, insofar as possible—with responding to requests for exercising data subject rights, and with DPIA/consultation obligations where applicable and where the Customer cannot reasonably fulfill them without Processor's help. During beta, response times and tooling may be limited; the Customer should submit requests to support@agentsmith.ch with sufficient detail.

    8. Return and deletion

    On termination of the Service (or on Customer's written request where agreed), Processor will delete or return personal data in accordance with the Privacy Policy and product deletion flows. Target: access removed promptly; completion of deletion typically within approximately 30 days, subject to backup cycles, security investigations, and mandatory legal retention.

    9. Audit

    The Customer may request information reasonably necessary to confirm compliance with this DPA. On-site audits may be agreed where required by law or a signed enterprise agreement, subject to confidentiality, security, and minimum-interruption constraints.

    10. Gaps and items not fully provable from code

    The following remain implementation or verification items. The published DPA describes targets and architecture; Customers should not treat this list as exhaustive assurance without their own diligence.

    • End-to-end retention matrix for every table, bucket, log stream, and backup generation (deletion within ~30 days across all copies).
    • OAuth / integration token encryption at rest—confirm production configuration and key management; do not assume from UI alone.
    • Optional tooling (e.g. Sentry, marketing analytics): confirm what is enabled in each environment.
    • Cookie / consent banner and blocking of non-essential scripts until consent (policy may precede full implementation).
    • EU representative under Art. 27 if required for Processor's processing—appoint and publish if applicable.
    • Formal registration of the Swiss entity and updates to party names and registration numbers in contracts.
    • AI vendor contract and account verification—confirm executed DPAs/SCCs, OpenRouter prompt-logging and training settings, and the retention terms of each direct-provider fallback before making a customer-specific zero-retention commitment.

    11. Enterprise SCC-aligned DPA

    This is a beta short-form DPA suitable for many early B2B relationships. Enterprise customers may request a full GDPR Article 28 + SCC package. Contact support@agentsmith.ch with company name, workspace, and jurisdiction.

    12. Assignment on incorporation

    The Processor is currently a Swiss sole proprietorship and intends to incorporate a Swiss company (Aktiengesellschaft or Gesellschaft mit beschränkter Haftung) with its seat in Zurich or Zug into which the Agent Smith business will be transferred. On that transfer:

    • the incorporated company becomes the Processor under this DPA and assumes the Processor's obligations in full, including those toward Customer personal data already processed;
    • the Customer receives advance written notice at the account contact address before the transfer takes effect;
    • the Customer may terminate the underlying agreement and this DPA before the transfer takes effect rather than accept the successor, in which case section 8 (Return and deletion) applies;
    • the subprocessor list, transfer safeguards and technical and organizational measures described in this DPA continue to apply to the successor unless and until the Customer is notified of a change under section 2.

    The Processor may also assign this DPA together with the underlying agreement in a restructuring, financing, merger or sale of the business, on the same notice and termination terms.

    Maintained as of 2026-08-16. Not legal advice. For the Customer's legal obligations as Controller, obtain independent counsel.