Legal
Data Processing Addendum
This addendum governs TryAgent's processing of personal data on behalf of customers and lists the subprocessors we use.
Last updated June 23, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer”) and TryAgent inc., a Delaware corporation (“TryAgent”) for the provision of the Service (the “Agreement”). It applies when TryAgent processes personal data in Customer Data on behalf of Customer under applicable data-protection laws, including the GDPR, UK GDPR, Swiss Federal Act on Data Protection, and the CCPA/CPRA. Capitalized terms not defined here have the meaning given in the Agreement.
1. Roles of the parties
For Customer Data, Customer is the controller or processor, and TryAgent is the processor or subprocessor. Each party will comply with its obligations under applicable data-protection laws. Customer is responsible for the lawfulness of Customer Data, the instructions it gives TryAgent, and any required notices, consents, assessments, or legal bases.
2. U.S. state privacy terms
Where U.S. state privacy laws apply, TryAgent acts as Customer's service provider, contractor, or processor for Customer Data. TryAgent will not sell or share Customer Data, retain, use, or disclose Customer Data outside the business purposes described in the Agreement, or combine Customer Data with personal data from other sources except as permitted by law. TryAgent will notify Customer if it determines it can no longer meet these obligations and will allow Customer to take reasonable steps to remediate unauthorized use of Customer Data.
TryAgent certifies that it understands and will comply with these restrictions. Customer may take reasonable and appropriate steps to monitor TryAgent's compliance, including through security summaries, questionnaires, audit reports, or other assessments described in Section 11. If TryAgent engages another person to help process Customer Data for a business purpose, TryAgent will bind that person to terms that provide at least the same level of privacy protection required by this DPA and applicable U.S. state privacy laws.
3. Scope and details of processing
- Subject matter: provision of human-in-the-loop escalation infrastructure for AI agent workflows.
- Duration: the term of the Agreement, plus the retention and deletion periods described in the Agreement and this DPA.
- Nature and purpose: hosting, routing, notifying, displaying, recording, auditing, recommending, and returning escalation decisions to customer workflows.
- Categories of data subjects:Customer's end users, personnel, reviewers, administrators, agents, and individuals referenced in escalation content.
- Categories of personal data: identifiers, contact data, account data, workflow metadata, escalation questions, evidence, choices, decisions, audit records, webhook delivery records, and any personal data Customer includes in Customer Data.
- Sensitive data:Customer must not submit protected health information, payment-card data, children's data, government identifiers, special-category data, or similar regulated data unless a separate written agreement expressly permits it.
4. Processing instructions
TryAgent will process Customer Data only on Customer's documented instructions, including the Agreement, this DPA, Customer's configuration of the Service, and Customer's use of the API, SDK, policies, destinations, webhooks, and integrations. TryAgent will inform Customer if, in its opinion, an instruction infringes applicable data-protection law, unless prohibited from doing so by law.
5. Confidentiality and personnel
TryAgent ensures that personnel authorized to process Customer Data are bound by confidentiality obligations and receive access only where needed to provide, secure, support, or maintain the Service.
6. Security measures
TryAgent maintains technical and organizational measures appropriate to the risk of the processing. Current measures include the controls in Annex A below. TryAgent may update these measures over time, provided the updates do not materially reduce the overall security of the Service.
7. Subprocessors
Customer gives TryAgent general authorization to engage subprocessors. TryAgent imposes data-protection obligations on subprocessors no less protective than those in this DPA and remains responsible for their performance. TryAgent will provide notice of intended material subprocessor changes by updating this page or giving other reasonable notice at least 30 days before the change. Shorter notice may apply only when a change is needed to address an emergency, security issue, legal requirement, or Customer-requested feature, in which case TryAgent will notify Customer as soon as reasonably practicable. Customer may object on reasonable data-protection grounds. If the parties cannot resolve an objection, Customer may stop using the affected feature or terminate the affected Service without penalty and receive a pro-rata refund of unused prepaid fees for the affected Service.
| Subprocessor | Purpose | Location | Scope |
|---|---|---|---|
| Google Cloud Platform | Cloud hosting, compute, database, queue, storage, and logging infrastructure | United States | Customer Data and service metadata |
| Auth0 (Okta, Inc.) | Authentication, identity management, organization membership, and session security | United States | Account and authentication data |
| Stripe, Inc. | Payment processing, subscription billing, invoices, and metered usage | United States | Billing data and limited account metadata |
| Slack (Salesforce, Inc.) | Escalation and notification delivery when a customer connects Slack | United States | Customer-configured notification content |
| Postmark (ActiveCampaign) | Transactional, system, and notification email delivery | United States | Email addresses and message content |
| OpenAI, L.L.C. | Default embeddings for learned recommendations | United States | Escalation questions and evidence sent for embeddings by default; not used to train OpenAI models |
| Google Analytics (Google LLC) | Website and product analytics, only when analytics are enabled | United States | Usage, device, and cookie data; not Customer Data content |
| PostHog, Inc. | Product analytics and frontend observability, only when optional analytics are enabled | United States | Usage, device, URL, route transition, and account/workspace identifier data; not Customer Data content |
8. International transfers
For restricted transfers from the EEA, the parties incorporate the European Commission's 2021 Standard Contractual Clauses as follows: Module Two applies when Customer is a controller and TryAgent is a processor; Module Three applies when Customer is a processor and TryAgent is a subprocessor. Clause 7 docking is optional, Clause 9 uses general authorization for subprocessors, and Clause 11 optional redress language is not used. Clause 17 and Clause 18 are governed by the law and courts of the EEA Member State where Customer is established, or, if Customer is not established in an EEA Member State, Ireland to the extent permitted by the SCCs.
For UK transfers, the UK International Data Transfer Addendum is incorporated with the tables completed by Annexes A, B, and C below, the ICO as competent supervisory authority, and the same SCC modules selected above. For Swiss transfers, references to the GDPR are interpreted to include the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent authority where required.
TryAgent will maintain reasonable transfer impact assessment information and make relevant information available to Customer on request, subject to confidentiality and security restrictions.
9. Assistance
Taking into account the nature of the processing, TryAgent will reasonably assist Customer with data-subject requests, security obligations, data-protection impact assessments, prior consultations, and responses to supervisory authorities. If TryAgent receives a data-subject request relating to Customer Data directly, it will direct the requester to Customer where legally permitted.
10. Personal data breaches
TryAgent will notify Customer without undue delay and, where feasible, within 48 hours after becoming aware of a personal data breach affecting Customer Data. TryAgent will provide information reasonably available to assist Customer in meeting its notification obligations, including the nature of the breach, categories of data affected, likely consequences, mitigation steps, and remediation status, as that information becomes available, including through phased updates when complete information is not yet available.
11. Audits
TryAgent will make available information reasonably necessary to demonstrate compliance with this DPA. Where available, TryAgent may satisfy audit requests through security summaries, policies, questionnaires, certifications, or third-party audit reports. Additional audits must be reasonable in scope, occur no more than once per year unless required after a material security incident, be conducted during normal business hours, and remain subject to confidentiality and security controls.
12. Deletion or return of data
On termination of the Agreement, TryAgent will, at Customer's choice, delete or return Customer Data, except to the extent retention is required by law or necessary for security, abuse prevention, billing, dispute resolution, or backup integrity. Unless the Agreement states otherwise, Customer Data is generally available for export for 30 days, deleted from active systems within 90 days, and deleted from backups in the ordinary backup cycle, typically within 180 days.
13. Learned recommendations and AI providers
Learned recommendations are on by default when the Service is configured with the applicable AI provider credentials. TryAgent sends escalation questions and evidence to OpenAI to generate embeddings and stores the resulting vectors in a tenant-scoped database. Recommendations are computed from prior reviewer decisions for the same tenant, policy, and workflow. TryAgent does not use Customer Data to train third-party foundation models for other customers unless Customer expressly agrees otherwise in writing. OpenAI may process API data for abuse monitoring for a limited period unless account-specific retention controls apply.
14. Liability and order of precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. If this DPA conflicts with the Agreement, this DPA controls for processing of Customer Data. The Standard Contractual Clauses control to the extent required for restricted transfers.
15. Contact
For data-protection matters, contact privacy@tryagent.ai.
Annex A. Technical and organizational measures
| Control area | Measures |
|---|---|
| Encryption and secrets | TLS for data in transit; encryption for managed storage; encrypted sensitive credentials at rest; secrets stored in managed secret stores or encrypted application records. |
| Access control | Role-based access, scoped API keys, least-privilege service accounts, tenant-scoped authorization, and access limited to personnel with a business need. |
| Tenant isolation | Tenant identifiers enforced in application authorization, data access paths, policies, audit events, API keys, and notification delivery records. |
| Logging and auditability | Audit records for security-relevant administrative actions, escalation lifecycle events, API key changes, webhook changes, and delivery history. |
| Secure development | Code review, typed validation, dependency review, environment separation, migration review, and vulnerability remediation based on severity. |
| Testing and assessment | Security review during material changes, dependency monitoring, production incident review, and remediation tracking based on risk. |
| Data minimization and retention | Customer-controlled escalation content, tenant-scoped learned vectors, documented deletion/export periods, and backup expiration through the ordinary backup cycle. |
| Data return and erasure | Customer Data export period after termination, active-system deletion timelines, backup deletion timelines, and preservation only for legal, security, abuse-prevention, billing, or dispute needs. |
| Incident response | Security incident intake, severity assessment, containment, customer notification workflow, remediation tracking, and post-incident review where appropriate. |
| Availability and recovery | Managed cloud infrastructure, database backups where configured, retry queues for delivery workflows, and incident response procedures. |
| Subprocessor management | Vendor selection based on role and risk, contractual data protection obligations, and maintenance of the public subprocessor list above. |
Annex B. Transfer details
- Data exporter: Customer, as identified in the Agreement.
- Data importer: TryAgent inc., c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808.
- Exporter role: Customer is the controller or processor, depending on its relationship with the personal data and end users.
- Importer role: TryAgent is the processor or subprocessor for Customer Data.
- Data subjects:Customer's end users, personnel, reviewers, administrators, agents, and individuals referenced in escalation content.
- Personal data transferred: identifiers, contact data, account data, workflow metadata, escalation questions, evidence, choices, decisions, audit records, webhook delivery records, and any personal data Customer includes in Customer Data.
- Sensitive data: prohibited unless a separate written agreement expressly permits it; if permitted, restrictions include purpose limitation, access controls, encryption where appropriate, training or authorization for personnel with access, and onward-transfer limits.
- Frequency: continuous for the term of the Agreement.
- Nature of processing: collection, hosting, storage, retrieval, display, transmission, notification, audit logging, default embedding for learned recommendations, deletion, and return of Customer Data.
- Purpose: providing and securing the Service.
- Retention: as described in Section 12 above and the Agreement.
- Transfers to subprocessors:subject matter, nature, and duration are the subprocessor's role in providing, securing, hosting, notifying, authenticating, billing, analyzing optional analytics, providing frontend observability, or embedding Customer Data for the Service during the Agreement term and applicable deletion period.
- Competent supervisory authority:for EEA transfers, the supervisory authority of the EEA Member State where Customer is established, or where otherwise required by Clause 13 of the SCCs; for UK transfers, the UK Information Commissioner's Office; for Swiss transfers, the Swiss Federal Data Protection and Information Commissioner.
Annex C. UK Addendum details
- Addendum parties: Customer as data exporter and TryAgent as data importer.
- Approved EU SCCs: the 2021 SCC modules selected in Section 8 above.
- Appendix information: Annex A, Annex B, and the subprocessor list above complete the relevant appendix tables.
- Ending the Addendum: neither party may end the UK Addendum under Section 19 of the mandatory clauses unless the applicable law or regulator requires replacement terms.