Data Processing Agreement
Last updated: July 11, 2026
Template — provided so agency customers of AgencyBrain can review our data-processing posture and technical/organizational measures when they themselves need to demonstrate GDPR compliance to their own clients. This is a starting template, not a signed legal instrument — contact us to execute a countersigned DPA for your organization.
1. Roles
When you use AgencyBrain to manage marketing data on behalf of your own clients, you ("the Customer") act as the Data Controller for that data, and Wahsol Technologies ("the Processor") processes it on your documented instructions, as configured through the Service.
2. Subject Matter & Duration
This DPA covers all personal data processed by the Service on the Customer's behalf — for example, client contact details entered into Leads, GMB reviews, or outreach records — for as long as the Customer maintains an active organization on the Service, plus any retention period described in §8.
3. Processor Obligations
- Process personal data only on the Customer's documented instructions (as expressed through normal use of the Service).
- Ensure personnel with data access are bound by confidentiality.
- Implement the technical/organizational measures described in §5.
- Assist the Customer in responding to data subject requests (access, rectification, erasure, portability) — the Service's own Settings → Data & Privacy export/delete tools are the primary self-serve mechanism; contact support for anything the UI doesn't cover.
- Notify the Customer without undue delay upon becoming aware of a personal data breach affecting their organization.
- Delete or return all personal data at the end of the engagement, at the Customer's choice, via the export tool followed by organization deletion.
4. Sub-Processors
The Customer authorizes the following sub-processors, listed in full in our Privacy Policy §4:
- Anthropic and Google (Gemini) — AI content generation
- Stripe — payment processing
- SerpApi — search rank tracking
- Pollinations.ai — optional AI image generation
- Our transactional email provider
We will notify Customers of any new sub-processor before it goes into effect, giving a reasonable window to object.
5. Technical & Organizational Measures
- Encryption at rest: BYOK AI provider keys and two-factor authentication secrets/recovery codes.
- Tenant isolation: every database query for tenant-owned data is scoped at the ORM level by default (deny-by-default, not opt-in filtering) — verified by an automated cross-tenant isolation test suite run on every change.
- Access control: role-based permissions (owner/admin/member/read-only-client) enforced server-side on every mutating action, not just hidden in the UI.
- Optional 2FA: TOTP-based two-factor authentication available to every account.
- Audit logging: security-relevant events (logins, permission changes, API token issuance, webhook configuration) are logged to an append-only audit trail.
- Platform operator access: support staff accessing a Customer's organization for troubleshooting do so in a read-only capacity — they cannot make changes on the Customer's behalf.
- Webhook/API security: outbound webhook payloads are HMAC-signed; API tokens are scoped per-organization and re-validated on every request, not just at issuance.
6. International Transfers
Sub-processors listed in §4 may process data outside the Customer's jurisdiction. Where required, transfers rely on that sub-processor's own compliance mechanism (e.g. Standard Contractual Clauses) — contact us for the specific mechanism relevant to your jurisdiction.
7. Audit Rights
On reasonable written request, we will provide the Customer with information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant security measures.
8. Data Return & Deletion
On termination, the Customer may export a full copy of their organization's data (Settings → Data & Privacy) at any time, then request deletion. A limited set of records — AI usage logs, security audit logs, billing records — are retained after deletion as an audit/compliance trail rather than active data, disconnected from any identifying organization reference.
9. Liability
Each party's liability under this DPA is subject to the limitation of liability provisions in our Terms of Service.
10. Contact
To request a countersigned DPA or ask questions about this template: hello@getknockly.com