Back to Home

Data Processing Addendum

Last updated: 26 September 2026

1. Scope and Roles

This addendum (“DPA”) forms part of the Terms of Service and applies when you (“Publisher”) publish a chatbot or MCP server built with AgentFoundry and we process personal data of your visitors on your behalf. For that data you are the controller (or business) and AgentFoundry is your processor (service provider). For data about you as our customer, and for our demo, the Privacy Policy applies and we are the controller.

2. What We Process, and Why

  • Subject matter and purpose: running your chatbot — answering visitors, keeping conversations, remembering visitors who agree, escalating to your support team, and measuring resolution.
  • Duration: while your bot is published, plus the retention periods below.
  • Data subjects: your website visitors and customers who chat or file complaints.
  • Types of data: chat messages (personal details redacted before AI processing), complaint details (name, email, text), an anonymous visitor id, usage events. We ask visitors not to enter sensitive data and try to remove it, but you should not build a bot that invites it.
  • Instructions: we process only on your documented instructions — your bot's configuration and these terms — and tell you if an instruction appears to break the law.

3. Confidentiality and Security

Everyone who can access the data is bound by confidentiality. We keep appropriate technical and organisational measures, including:

  • encryption in transit (HTTPS) and at rest (database provider);
  • a database closed to public access, with server-side keys only, and verified automatically;
  • redaction of personal details before AI processing, and requests routed to AI providers that do not store prompts or train on them;
  • complaint details visible only to the person who filed them and the operator;
  • rate limiting, access tokens for operator functions, and logs that contain no message text;
  • automated deletion (section 6).

4. Sub-processors

You authorise us to use the sub-processors below, under written terms no less protective than this DPA. We will update this page at least 30 days before adding or replacing one; if you object on reasonable data-protection grounds you may stop using the service and we will delete your data.

Sub-processors
Sub-processorPurposeDataLocationSafeguard
OpenRouter (and the model providers behind it: OpenAI, Cohere, TypeSafe AI …)Writes replies, reads tone, embeds and re-ranks knowledge-base textRedacted visitor messages; your knowledge-base textUnited StatesRequests ask for providers that do not store prompts or train on them
SupabaseDatabaseConversations, complaints, usage events, your bot settings and knowledge baseThe region chosen for the project (AWS)Encrypted at rest; closed to public access
Mem0Remembered notes (only for visitors who agreed)Short notes about what a consenting visitor asked, under a random idUnited StatesNotes deleted after 30 days
RenderPersonal-data detection and answer-quality scoringVisitor messages (to find names) and sample conversationsUnited StatesProcessed in memory, not stored
VercelHostingEverything in transit; request logsUnited States (iad1) and edge networkLog retention per Vercel
Sentry (only if enabled)Error reportsError details, no message textUnited States—

5. International Transfers

Data may be processed outside your country, including in the United States. Where a transfer needs a legal mechanism, the EU Standard Contractual Clauses (Module 2, controller to processor, and Module 3 for onward transfers) and the UK International Data Transfer Addendum are incorporated by reference, with the details in this DPA as their annexes, and we rely on our sub-processors' equivalent safeguards.

6. Retention, Return and Deletion

  • Conversations, usage events and remembered notes are deleted automatically 30 days after they were created; resolved complaints 30 days after resolution, unresolved ones after 180 days.
  • Visitors can erase their own data at any time with “Forget me”.
  • When you delete a bot or end the service, we delete its remaining data within 30 days on request, and confirm by email. Copies in providers' backups age out on their schedules.

7. Helping You Meet Your Obligations

We help you answer visitors' requests (access, deletion, correction, objection) and carry out your security, breach-notification and impact-assessment duties, by email to expensemanagementvj@gmail.com. If a visitor contacts us directly about data we hold for you, we tell them to contact you unless the law requires us to answer. We can find complaint data by email address and chat data by the visitor's anonymous id; we cannot identify a person from a chat alone.

8. Personal-Data Breaches

We tell you without undue delay, and in any case within 72 hours, after becoming aware of a breach affecting your data, with what we know: what happened, the data and people affected, likely consequences and what we are doing. We keep taking steps to contain it and update you as we learn more.

9. Information and Audits

On request we give you the information needed to show we comply with this DPA — including the automated checks that cover database access, retention and redaction — and reasonably cooperate with an audit by you or a regulator, no more than once a year unless a regulator or a breach requires it, at your cost and without exposing other customers' data.

10. Liability and Order of Precedence

Liability under this DPA is subject to the limits in the Terms of Service, except where the law does not allow them. If this DPA and the Terms conflict on personal data, this DPA wins; if the Standard Contractual Clauses apply and conflict with either, the Clauses win. This DPA is governed by the laws of India (and, for the Clauses, the law they require).