1. Scope and roles
This Data Processing Addendum ("DPA") forms part of the AgentLoka Terms of Service between Customer (the "Data Controller") and AgentLoka, Inc. (the "Data Processor"). It governs the processing of Personal Data on behalf of Customer in connection with the Service.
Where Customer's Buyers are themselves controllers (e.g., a B2B SaaS reselling AgentLoka-powered features), Customer remains responsible for instructing its sub-customers and obtaining the necessary lawful bases.
2. Processing instructions
We process Personal Data only on documented instructions from Customer, including: configuring and executing Agents Customer creates or hires; storing run inputs, outputs, and audit log entries; delivering webhooks; sending receipts and notifications. We will not process Personal Data for any other purpose unless required by applicable law.
3. Confidentiality of personnel
Every AgentLoka employee or contractor with access to Personal Data is bound by written confidentiality obligations and receives security training at onboarding and annually thereafter.
4. Security measures
We maintain appropriate technical and organisational measures ("TOMs") to protect Personal Data. The current TOMs are summarised on /security and include, at minimum:
- AES-256 encryption at rest (AWS KMS, customer-managed keys on Business tier);
- TLS 1.3 enforced end-to-end with HSTS preload;
- Per-workspace credential isolation; row-level security in Postgres;
- Append-only, signed, chained audit log;
- Multi-AZ Postgres with cross-region backup; RPO 5 min / RTO 1 hour;
- Annual third-party penetration test; SOC 2 Type II in progress;
- Quarterly review of LLM tool-call safety rails (schema validation, scope checks).
5. Sub-processors
The current list of sub-processors is maintained at /legal/subprocessors. Customer authorises AgentLoka to engage these sub-processors. We notify Customer at least 30 days before adding a new sub-processor (or removing one materially); Customer may object on reasonable grounds and may terminate the affected Service if the objection cannot be resolved.
We have a written DPA in place with each sub-processor that imposes equivalent obligations to those in this DPA.
6. International transfers
Where Personal Data is transferred outside the EEA, UK, Switzerland, or India, we rely on Standard Contractual Clauses (SCCs) or, where available, an adequacy decision. EU and India workspaces are region-pinned to EU-Frankfurt and AP-Mumbai respectively; data does not leave the region for inference, storage, or logs.
7. Data subject rights
We assist Customer in responding to data-subject requests under applicable law. Workspace admins can export and delete personal data from Settings → Workspace; the audit log is exportable to S3 / GCS / Azure Blob on Business tier. Requests routed to AgentLoka will be forwarded to Customer within 7 days.
8. Personal data breach
We notify Customer without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer's data. The notification includes the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and the measures taken or proposed.
9. Audits
Once per year (or more often if required by law or following a material breach), Customer may request a copy of our then-current SOC 2 report and pen-test summary under NDA. Where Customer needs an on-site audit, we'll cooperate at reasonable notice and at Customer's expense.
10. Termination and return of data
On termination, we return or delete Personal Data within 30 days unless retention is required by law. Audit log entries and billing records are retained per the schedule in our Privacy Policy.
11. Contact
For DPA-related questions or to request a signed copy, email legal@agentloka.com.
Questions, redlines, or just curious? Email legal@agentloka.com. For the security posture that backs these terms, see /security.