How to execute: This DPA is pre-signed by AgentGate. To make it binding, your company must (1) complete the fields in Annex I below, (2) countersign via email to bakhrom@agengate.com, and (3) retain a copy for your records. For custom negotiations or Enterprise customers, we accept your company's DPA template.
Table of Contents
  1. Definitions
  2. Subject Matter & Duration
  3. Processor Obligations
  4. Security Measures
  5. Subprocessors
  6. International Transfers
  7. Data Subject Rights
  8. Breach Notification
  9. Audit Rights
  10. Termination & Return of Data
  11. Annex I: Processing Details
  12. Annex II: Technical & Organizational Measures

1. Definitions

Capitalized terms have the meanings given in the EU General Data Protection Regulation (GDPR) and the UK GDPR. In particular:

2. Subject Matter & Duration

This DPA governs AgentGate's processing of Customer Data as a Processor on behalf of Customer (the Controller), for the sole purpose of providing the Services. This DPA takes effect when Customer accepts it and remains in force for the duration of Customer's subscription to the Services.

3. Processor Obligations

AgentGate will:

  1. Process Customer Data only on documented instructions from Customer (typically via the API);
  2. Ensure that personnel authorized to process Customer Data are bound by confidentiality;
  3. Implement appropriate technical and organizational measures (see Annex II);
  4. Not engage any new Subprocessor without notice (see Section 5);
  5. Assist Customer in responding to data subject rights requests;
  6. Assist Customer with security, breach notification, and impact assessment obligations;
  7. Delete or return Customer Data at the end of the Services (see Section 10);
  8. Make available information necessary to demonstrate compliance with Article 28 GDPR.

4. Security Measures

AgentGate implements and maintains the technical and organizational security measures described in Annex II. These measures include, at minimum:

Full details are available in the Trust Center and Security Questionnaire.

5. Subprocessors

Customer provides general authorization for AgentGate to engage Subprocessors for the provision of the Services. The current list of Subprocessors is maintained in the Trust Center § 7.

AgentGate will:

Customer may object to a new Subprocessor in writing within 14 days of notice. If the objection cannot be resolved, Customer may terminate the Services and receive a pro-rata refund for unused time.

6. International Transfers

Customer Data may be processed in the EU, UK, and US (subprocessors). Where data is transferred outside the EEA / UK:

7. Data Subject Rights

Taking into account the nature of the processing, AgentGate will assist Customer in fulfilling its obligations under Articles 12–23 GDPR, including requests to:

Customer may submit such requests to bakhrom@agengate.com. AgentGate will respond within 30 days.

8. Personal Data Breach Notification

AgentGate will notify Customer of any Personal Data Breach without undue delay and in any event within 72 hours of becoming aware. Notification will include:

AgentGate will cooperate with Customer's breach response and notification obligations.

9. Audit Rights

Customer may audit AgentGate's compliance with this DPA by:

10. Termination & Return of Data

Upon termination of the Services:

Annex I: Processing Details

A. List of Parties

RoleControllerProcessor
Name [Customer Company Name] Bakhrom Berdiyev d/b/a AgentGate
Contact [Customer DPO / Privacy Contact] bakhrom@agengate.com
Address [Customer Address] [AgentGate Address on file]

B. Description of Processing

ItemDescription
Subject matterValidation of AI agent outputs against compliance gates.
DurationFor the duration of Customer's subscription plus retention periods in § 10.
Nature & purposeAutomated compliance validation, audit logging, and evidence chain generation.
Categories of data subjectsEnd users of Customer's AI systems whose data may appear in submitted agent output.
Categories of personal dataAs determined by Customer's usage. May include: names, email addresses, account identifiers, transaction details, or other data contained in agent output.
Special categoriesNone processed by default. Customer must not submit special-category data without appropriate safeguards.
RetentionRaw agent output: not persisted (in-memory only). Metadata and hashes: 90 days (Free) / 12 months (Paid).

C. Transfers

Processing occurs primarily in the EU (VPS hosting, Supabase EU region). Subprocessors in the US are engaged under Standard Contractual Clauses and/or EU-US Data Privacy Framework. See Trust Center § 7.

Annex II: Technical & Organizational Measures

Access Control

Encryption

Network Security

Monitoring & Logging

Backup & Recovery

Personnel

Incident Response

Ready to execute?

Email bakhrom@agengate.com with:

  1. A countersigned copy of this DPA (PDF or DocuSign);
  2. Completed Annex I fields (your company name, contact, address);
  3. Any company-specific amendments you'd like to propose.

We respond within 2 business days. Enterprise customers may alternatively propose their own DPA template — we'll review and return redlines within 5 business days.

Legal note: This DPA is a standard template for general B2B use. It is not legal advice. Consult your legal counsel before execution. AgentGate reserves the right to update this template; material changes will be communicated at least 30 days in advance.