Data Processing Agreement
Effective: 2026-05-10
This page is the human-facing summary of Coagentic's Data Processing Agreement (DPA). The DPA forms part of every B2B customer contract and governs how Coagentic processes Personal Data on your behalf as a Processor under the GDPR, the UK GDPR, the Swiss FADP, the California CCPA/CPRA, and Türkiye's KVKK.
What it covers
- Roles, scope, duration, and lawful basis for processing.
- Confidentiality and security commitments (Annex A).
- Sub-processor approvals and notification (Annex B).
- EU SCCs and UK IDTA for international transfers.
- CCPA/CPRA service-provider terms.
- KVKK addendum for customers in Türkiye.
- Personal-Data-Breach notification within 72 hours.
- Audit rights and post-termination data deletion.
How to execute
By using the Services on or after the effective date above, your workspace is automatically covered by the DPA — no signature required. If your procurement team needs a counter-signed PDF, email [email protected] with your workspace ID and we'll return one within 10 business days.
Full text
The current list of authorised sub-processors is maintained at /legal/subprocessors.